<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint option for DMZ-based update server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/243459#M47303</link>
    <description>&lt;P&gt;Speaking of headaches and PTCs, the firewalls which use the PTCs have been failing to get updates for a few days.&amp;nbsp;The PTC health report said everything is fine. Turns out the certificates the PTCs present for the name updates.checkpoint.com just expired with no warning, and that isn't checked in the health report.&lt;/P&gt;
&lt;P&gt;It's a minor issue, but frustrating. Cost some coworkers a few hours trying to figure out what was going on.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Mar 2025 18:13:39 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2025-03-10T18:13:39Z</dc:date>
    <item>
      <title>Checkpoint option for DMZ-based update server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239504#M46462</link>
      <description>&lt;P&gt;Hello Checkmates --&lt;/P&gt;
&lt;P&gt;What are checkpoint options for deployment of dedicated "update server" to be placed on DMZ allowing Security Gateways to receive updates for advanced blade features.&lt;/P&gt;
&lt;P&gt;This not a new topic for certain Govt networks and Utility SCADA networks where Internet isolation is best practice.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The keys:&lt;/P&gt;
&lt;P&gt;1) advanced features enabled on Checkpoint gateways:&amp;nbsp;&amp;nbsp; IPS, Antibot, AppCtl.&lt;/P&gt;
&lt;P&gt;2) checkpoint gateway can't talk outside local network (ie.&amp;nbsp;&amp;nbsp; can't communicate directly with Checkpoint public update servers).&lt;/P&gt;
&lt;P&gt;3) granular communication to specific "update server" on DMZ is permissible. &amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Advise on thoughts.&amp;nbsp;&amp;nbsp;&amp;nbsp; thx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 21:25:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239504#M46462</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2025-01-23T21:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint option for DMZ-based update server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239506#M46463</link>
      <description>&lt;P&gt;The term you should ask about is "Private Threat Cloud" or PTC. My environment has some. I&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;strongly&lt;/STRONG&gt;&lt;/EM&gt; recommend against them. They've given us nothing but headaches.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 21:38:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239506#M46463</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-01-23T21:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint option for DMZ-based update server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239507#M46464</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;-- thanks for the quick reply and insight.&lt;/P&gt;
&lt;P&gt;Yes -- I suggest the customer will be excited about solution:&lt;/P&gt;
&lt;P&gt;1) not a headache&lt;/P&gt;
&lt;P&gt;2) no additional cost&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 21:40:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239507#M46464</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2025-01-23T21:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint option for DMZ-based update server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239510#M46466</link>
      <description>&lt;P&gt;PTC or a Proxy are the solutions that come to mind.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 22:50:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239510#M46466</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-01-23T22:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint option for DMZ-based update server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239518#M46472</link>
      <description>&lt;P&gt;IPS and App Control have actual signatures that can be downloaded.&lt;BR /&gt;Most everything else is a dynamic lookup to ThreatCloud, for which you would need Private ThreatCloud:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk149692" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk149692&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 00:45:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/239518#M46472</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-24T00:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint option for DMZ-based update server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/243459#M47303</link>
      <description>&lt;P&gt;Speaking of headaches and PTCs, the firewalls which use the PTCs have been failing to get updates for a few days.&amp;nbsp;The PTC health report said everything is fine. Turns out the certificates the PTCs present for the name updates.checkpoint.com just expired with no warning, and that isn't checked in the health report.&lt;/P&gt;
&lt;P&gt;It's a minor issue, but frustrating. Cost some coworkers a few hours trying to figure out what was going on.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 18:13:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-option-for-DMZ-based-update-server/m-p/243459#M47303</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-03-10T18:13:39Z</dc:date>
    </item>
  </channel>
</rss>

