<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Air-gapped endpoints in environment using EpmaaS. in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249382#M10578</link>
    <description>&lt;P&gt;Updating Signatures offline needs an On-Premise EPSS&amp;nbsp; Management Server as documented in &lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk182535&lt;/SPAN&gt;&lt;/SPAN&gt;. So you can ask CP TAC if Infinity EPS could be used, but but signature update, using a TE appliance and its update will not be possible.&lt;/P&gt;</description>
    <pubDate>Tue, 20 May 2025 11:36:10 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2025-05-20T11:36:10Z</dc:date>
    <item>
      <title>Air-gapped endpoints in environment using EpmaaS.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249378#M10577</link>
      <description>&lt;P&gt;One of our customers is using Infinity Harmony Endpoint for regular endpoints like computers, servers.&lt;/P&gt;
&lt;P&gt;They have a requirement to deploy a few computers which would be in a completely isolated network and location for accessing and managing privileged information.&lt;/P&gt;
&lt;P&gt;The framework requires a standalone EDR solution.&lt;/P&gt;
&lt;P&gt;I've read&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182535" target="_blank" rel="noopener"&gt;Deploying Harmony Endpoint in an Offline (Air-Gapped) Environment&lt;/A&gt;&amp;nbsp;which describes a completely offline installation of EPS server along with TE appliance.&lt;/P&gt;
&lt;P&gt;As the customer is already using the online Endpoint, the question is whether we can leverage the existing option of creating a full standalone package, including signatures, installing locally and leave it offline, knowing the limitations of blades when offline, and update the signatures manually without access to any management server.&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 11:09:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249378#M10577</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-05-20T11:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Air-gapped endpoints in environment using EpmaaS.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249382#M10578</link>
      <description>&lt;P&gt;Updating Signatures offline needs an On-Premise EPSS&amp;nbsp; Management Server as documented in &lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk182535&lt;/SPAN&gt;&lt;/SPAN&gt;. So you can ask CP TAC if Infinity EPS could be used, but but signature update, using a TE appliance and its update will not be possible.&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 11:36:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249382#M10578</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-05-20T11:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Air-gapped endpoints in environment using EpmaaS.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249392#M10579</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could use the supernode, the link is below. In addition, you could implement the endpoint firewall, only allowing access to the supernode.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_HarmonyEndpointWebManagement_AdminGuide/Topics-HEPWM-R81.10/Super-Node.htm" target="_self"&gt;Super-Node&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 12:52:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249392#M10579</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-05-20T12:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Air-gapped endpoints in environment using EpmaaS.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249393#M10580</link>
      <description>&lt;P&gt;Also the supernode needs internet access, so it can not be used in a completely isolated network !&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 13:27:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249393#M10580</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-05-20T13:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Air-gapped endpoints in environment using EpmaaS.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249397#M10581</link>
      <description>&lt;P&gt;tks&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 11:20:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249397#M10581</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-05-21T11:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Air-gapped endpoints in environment using EpmaaS.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249407#M10582</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/87055"&gt;@lluner&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;Thanks for chiming in.&lt;/P&gt;
&lt;P&gt;This project has stringent requirements, so partial or derived Internet access like the super node is not compliant.&lt;/P&gt;
&lt;P&gt;We will then explore if the air-gapped architecture with HEP can be considered.&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 16:26:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249407#M10582</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-05-20T16:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: Air-gapped endpoints in environment using EpmaaS.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249465#M10584</link>
      <description>&lt;P&gt;Please, do not adress me in a language i do not understand.&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 07:46:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249465#M10584</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-05-21T07:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Air-gapped endpoints in environment using EpmaaS.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249730#M10585</link>
      <description>&lt;P&gt;You could ask you SE if Check Point will support a data diode. For example Owl.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2025 19:40:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Air-gapped-endpoints-in-environment-using-EpmaaS/m-p/249730#M10585</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-05-23T19:40:24Z</dc:date>
    </item>
  </channel>
</rss>

