<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sandblast - Proxy - HTTPS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7583#M14096</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically, what the fix here provides is the ability to turn your gateway into an ICAP server:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111306" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111306"&gt;Check Point support for Internet Content Adaptation Protocol (ICAP) server&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This allows your proxy to consult the Check Point Threat Emulation blade on the Security Gateway to determine if the file downloaded is benign or malicious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's worth noting that this hotfix, while considered GA, it is not integrated into a major release (i.e. not part of R80.10).&lt;/P&gt;&lt;P&gt;You also may have issues applying other hotfixes on top of this release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Oct 2017 00:54:05 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-10-17T00:54:05Z</dc:date>
    <item>
      <title>Sandblast - Proxy - HTTPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7582#M14095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We currently run a 2-node VSX cluster w/R77.30 and are looking to implement TE with the gateways forwarding to the ThreatCloud for Emulation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our environment uses a Intel web gateway as a forward proxy - so we are trying to understand the options available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im hearing ICAP might be an option - but there isn’t really any information about it other than one SK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’m just looking for more information on what deployment options might be available.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 22:13:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7582#M14095</guid>
      <dc:creator>dd84</dc:creator>
      <dc:date>2017-10-16T22:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast - Proxy - HTTPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7583#M14096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically, what the fix here provides is the ability to turn your gateway into an ICAP server:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111306" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111306"&gt;Check Point support for Internet Content Adaptation Protocol (ICAP) server&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This allows your proxy to consult the Check Point Threat Emulation blade on the Security Gateway to determine if the file downloaded is benign or malicious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's worth noting that this hotfix, while considered GA, it is not integrated into a major release (i.e. not part of R80.10).&lt;/P&gt;&lt;P&gt;You also may have issues applying other hotfixes on top of this release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Oct 2017 00:54:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7583#M14096</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-17T00:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast - Proxy - HTTPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7584#M14097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response Daemon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this the only supported deployment model in an environment that utilizes a forward proxy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We were told that running the Sandblast Browser Agent would work - but we haven’t been able to get it functioning correctly with TAC and believe there is a limitation with forward proxy and SBA4B. &amp;nbsp;Correct me if you believe otherwise?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Oct 2017 01:00:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7584#M14097</guid>
      <dc:creator>dd84</dc:creator>
      <dc:date>2017-10-17T01:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast - Proxy - HTTPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7585#M14098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;For the above solution I mentioned, yes, that is correct.&lt;/P&gt;&lt;P class=""&gt;SBA4B is a different way to solve the same problem but the client sends the files to ThreatCloud, returning either a “safe” version of the file, the original (if it’s safe), or block the download if it is malicious.&lt;/P&gt;&lt;P class=""&gt;I am not aware of any issues with proxies and SBA4B but maybe &lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.checkpoint.com/people/arzile9338099-64b6-3d9b-be29-fc67dc1788f6"&gt;Lior Arzi&amp;nbsp;&lt;/A&gt;or someone on his team can comment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Oct 2017 23:12:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7585#M14098</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-17T23:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast - Proxy - HTTPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7586#M14099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ICAP Server HF is integrated with the current JHF286.&lt;/P&gt;&lt;P&gt;But I am not sure about support of ICAP HF on VSX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can however install a separate CP GW with R77.30 and use ICAP HF there to emulate files in the cloud received from your proxy. So you might give it a try ...&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 13:38:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sandblast-Proxy-HTTPS/m-p/7586#M14099</guid>
      <dc:creator>Thomas_Werner</dc:creator>
      <dc:date>2017-10-27T13:38:16Z</dc:date>
    </item>
  </channel>
</rss>

