<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Policy Server in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/75079#M2019</link>
    <description>&lt;P&gt;Can we submit feature requests for future releases/fixes?&amp;nbsp; In a large environment with 100's of sites the way policy servers work really hamper the network when it comes to client upgrades.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy updates, or AntiMalware upgrades are great when using a policy server.&amp;nbsp; But not when it comes to installing a new 700MB client on 5000 machines.&amp;nbsp; A client should always look to use a policy server on it's own subnet for a client upgrade, not one over the WAN link.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2020 10:47:50 GMT</pubDate>
    <dc:creator>J_B</dc:creator>
    <dc:date>2020-02-13T10:47:50Z</dc:date>
    <item>
      <title>Endpoint Policy Server</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/74709#M1980</link>
      <description>&lt;P&gt;When pushing out new clients to devices, does the Endpoint Policy Server handle this, or will the new client be downloaded from the Primary Management Server?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was almost sure that the client would be downloaded from the Policy Server that the client is connected to, but it's not really clear within the documentation as it doesn't specify client upgrades?&amp;nbsp; We're gradually updating 4000+ clients and the comms links are getting hammered, almost as if all the client downloads are coming from the Primary Management Server.&lt;/P&gt;&lt;P class="tpbodytext"&gt;&lt;FONT size="2"&gt;&lt;EM&gt;The Endpoint Policy Server handles the most frequent and bandwidth-consuming communication. The Endpoint Policy Server handles these requests without forwarding them to the Endpoint Security Management Server:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;UL class="listbullet"&gt;&lt;LI&gt;&lt;FONT size="2"&gt;&lt;EM&gt;All heartbeat and synchronization requests.&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Policy downloads&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Anti-Malware updates&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;&lt;EM&gt;All Endpoint Security client logs (the Endpoint Policy Server is configured as Log Server by default).&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;It would be great if you could restrict the Policy Servers to only communicate with certain subnets that you specify, a bit like what you can do with distribution points within SCCM.&amp;nbsp; There doesn't seem to be any real logic behind the proximity analysis, apart from a simple ping command.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 16:31:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/74709#M1980</guid>
      <dc:creator>J_B</dc:creator>
      <dc:date>2020-02-10T16:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Policy Server</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/74888#M2008</link>
      <description>It uses ping to determine proximity analysis, you are correct.&lt;BR /&gt;I assume you could restrict access to the Policy Server using a firewall rule if needed.</description>
      <pubDate>Wed, 12 Feb 2020 01:57:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/74888#M2008</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-12T01:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Policy Server</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/75079#M2019</link>
      <description>&lt;P&gt;Can we submit feature requests for future releases/fixes?&amp;nbsp; In a large environment with 100's of sites the way policy servers work really hamper the network when it comes to client upgrades.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy updates, or AntiMalware upgrades are great when using a policy server.&amp;nbsp; But not when it comes to installing a new 700MB client on 5000 machines.&amp;nbsp; A client should always look to use a policy server on it's own subnet for a client upgrade, not one over the WAN link.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 10:47:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/75079#M2019</guid>
      <dc:creator>J_B</dc:creator>
      <dc:date>2020-02-13T10:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Policy Server</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/75205#M2029</link>
      <description>The naive question I have is: shouldn't the policy server in your network have lower latency than one over the WAN link?&lt;BR /&gt;In any case, the formal link to submit RFEs: &lt;A href="https://rfe.checkpoint.com/rfe/rfe.htm" target="_blank"&gt;https://rfe.checkpoint.com/rfe/rfe.htm&lt;/A&gt;&lt;BR /&gt;If it's a deal breaker, I highly recommend working with your local office.</description>
      <pubDate>Thu, 13 Feb 2020 19:45:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/75205#M2029</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-13T19:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Policy Server</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/75259#M2036</link>
      <description>&lt;P&gt;They're fast WAN links so the latency is negligible across most of the sites.&amp;nbsp; Until of course clients start running client upgrades across all the WAN links instead of just using the policy server on their own subnet.&lt;/P&gt;&lt;P&gt;Thanks for the link.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 09:16:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Policy-Server/m-p/75259#M2036</guid>
      <dc:creator>J_B</dc:creator>
      <dc:date>2020-02-14T09:16:55Z</dc:date>
    </item>
  </channel>
</rss>

