<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Prevention policy configuration when HTTP emulation on Private Cloud Appliance in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63723#M13310</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Bildschirmfoto 2019-09-26 um 10.52.17.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2632i7C97B6BDAD357308/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2019-09-26 um 10.52.17.png" alt="Bildschirmfoto 2019-09-26 um 10.52.17.png" /&gt;&lt;/span&gt;No - i have a separate TP policy for GWs (with enabled AV, ABOT, IPS and TE on remote appliance) and for TE (only TE enabled&amp;nbsp;with local emulation).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Sep 2019 08:54:35 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-09-26T08:54:35Z</dc:date>
    <item>
      <title>Threat Prevention policy configuration when HTTP emulation on Private Cloud Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63458#M13305</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TE - Copy - Copy.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2629i57D004D0B06EBE93/image-size/large?v=v2&amp;amp;px=999" role="button" title="TE - Copy - Copy.png" alt="TE - Copy - Copy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Pls help me for the configuration.&lt;/P&gt;&lt;P&gt;As per the Diagram, we have Gateway with TE Appliance.&lt;/P&gt;&lt;P&gt;So basically we are using TE appliance only for emulation, not for extraction, ThreatExtraction happening on Gateway.&lt;/P&gt;&lt;P&gt;So for any file we are download from the Internet then first come to the gateway then gateway sends that file to TE for emulation then TE gives the verdict to Gateway then gateway sends the file to the end-user base on the policy. Correct me I am wrong.&lt;/P&gt;&lt;P&gt;I need a clear idea about configuration and working.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this required to set Threat Prevention policy&amp;nbsp; as Detect mode in TE Policy Package 2 ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If I enable Threat Extraction on TE policy package 2 then?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 07:26:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63458#M13305</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-09-26T07:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention policy Configuration when HTTP emulation on Private Cloud Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63460#M13306</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your diagram and notes seem correct. I would recommend to set the policy on detect the first few days so you can see how it works.&lt;/P&gt;&lt;P&gt;Another important part is to decide the file extensions that you will be checking and if you want to go with a fail open or fail close policy for your emulations.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 16:13:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63460#M13306</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-09-23T16:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention policy Configuration when HTTP emulation on Private Cloud Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63708#M13307</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28479"&gt;@FedericoMeiners&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick response.&lt;/P&gt;&lt;P&gt;I need to understand which one is the best practise to&amp;nbsp; "set TE policy package threat prevention profile mode as DETECT or Prevent".&lt;/P&gt;&lt;P&gt;I also need to understand, as per my current scenario If&amp;nbsp; am enable the Threat Extraction on&amp;nbsp;TE policy package threat prevention profile then?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 06:13:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63708#M13307</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-09-26T06:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention policy configuration when HTTP emulation on Private Cloud Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63711#M13308</link>
      <description>&lt;P&gt;I must confess that your diagram confuses me ! I have a similar (LAB) configuration with a single GW instead of a cluster and a local TE appliance. But i have configured it differently:&lt;/P&gt;
&lt;P&gt;- My TE has only FW and TE blades enabled - i see no point in enabling ABot and AV in both GW and TE. As the GW AV will check the hash before sending to TE, AV on TE seems useless.&lt;/P&gt;
&lt;P&gt;- TE does three passes for a verdict and the sums it up. There is no confidence level involved here, as the GW will send according to File Type and size only to TE and TX&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 07:08:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63711#M13308</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-26T07:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention policy configuration when HTTP emulation on Private Cloud Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63720#M13309</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the update. I updated my diagram.&lt;/P&gt;&lt;P&gt;So basically you mean to say that, there not required to create a separate policy package for TE appliance.&lt;/P&gt;&lt;P&gt;So when I will install the Threat prevention policy on standard policy package then it needs to select the TE object as well? ,&lt;/P&gt;&lt;P&gt;Correct me If I am wrong.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chinmaya_Naik&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 08:31:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63720#M13309</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-09-26T08:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention policy configuration when HTTP emulation on Private Cloud Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63723#M13310</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Bildschirmfoto 2019-09-26 um 10.52.17.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2632i7C97B6BDAD357308/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2019-09-26 um 10.52.17.png" alt="Bildschirmfoto 2019-09-26 um 10.52.17.png" /&gt;&lt;/span&gt;No - i have a separate TP policy for GWs (with enabled AV, ABOT, IPS and TE on remote appliance) and for TE (only TE enabled&amp;nbsp;with local emulation).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 08:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63723#M13310</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-26T08:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention policy configuration when HTTP emulation on Private Cloud Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63731#M13311</link>
      <description>&lt;P&gt;What is important for your configuration:&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR valign="top"&gt;
&lt;TD&gt;Cluster&lt;/TD&gt;
&lt;TD&gt;
&lt;UL&gt;
&lt;LI&gt;Threat Emulation local cache is &lt;EM&gt;not&lt;/EM&gt; synchronized.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114806&amp;amp;partition=Advanced&amp;amp;product=Threat" target="_blank"&gt;sk114806: ATRG: Threat Emulation&amp;nbsp;&lt;/A&gt;and&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102309" target="_blank" rel="noopener"&gt;sk102309 - Threat Emulation support for Multiple Private Cloud Appliances&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 10:43:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63731#M13311</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-26T10:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention policy configuration when HTTP emulation on Private Cloud Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63736#M13312</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the update.&lt;/P&gt;&lt;P&gt;Find the below screenshot.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TE1.png" style="width: 969px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2633iDE980BFB80894F1A/image-size/large?v=v2&amp;amp;px=999" role="button" title="TE1.png" alt="TE1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TE2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2636iC72C22F33ABAD247/image-size/large?v=v2&amp;amp;px=999" role="button" title="TE2.png" alt="TE2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TE3.png" style="width: 984px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2634i8F39B8B30E050A4A/image-size/large?v=v2&amp;amp;px=999" role="button" title="TE3.png" alt="TE3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TE4.png" style="width: 989px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2635i9C7E3C7192C505B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="TE4.png" alt="TE4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As last screenshot ,&amp;nbsp; this is what I need to know that what I need to set on Activation Mode.&lt;/P&gt;&lt;P&gt;Still, I am not face any issue, I need to understand the proper configuration because I see some different configuration on two different places but still both are working.&lt;/P&gt;&lt;P&gt;Thank You&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chinmaya Naik&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 10:55:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/63736#M13312</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-09-26T10:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention policy configuration when HTTP emulation on Private Cloud Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/99620#M13313</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Pls give me a clarification on this.&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 16:53:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Threat-Prevention-policy-configuration-when-HTTP-emulation-on/m-p/99620#M13313</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2020-10-20T16:53:03Z</dc:date>
    </item>
  </channel>
</rss>

