<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: connections to file-rep.iaas.checkpoint.com:443 in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236323#M9846</link>
    <description>&lt;P&gt;Yes, the supernode has connectivity to the Cloud without the proxy. All these connections we can see on the proxy are only from the clients with installed EndPoint software.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Dec 2024 09:55:01 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2024-12-19T09:55:01Z</dc:date>
    <item>
      <title>connections to file-rep.iaas.checkpoint.com:443</title>
      <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236319#M9844</link>
      <description>&lt;P&gt;After deploying Harmony Endpoint in an environment with internet access only with proxy we are facing CPU utilization problems on the proxy environment.&lt;/P&gt;
&lt;P&gt;From the proxy logs we see the system is flooded with connections to "file-rep.iaas.checkpoint.com" from all clients all the times. We are using a supernode in the environment but these connections are always seen via the proxy. Around 80% of all internet traffic is regarding this connections. sk116590 states this connections are for ThreatEmulationBlade&lt;/P&gt;
&lt;P&gt;Any chance to stop this or get working not via the proxy but the supernode?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2024-12-19 10_.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28920iD2B325318AFA9D0A/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-12-19 10_.png" alt="2024-12-19 10_.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 09:31:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236319#M9844</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-12-19T09:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: connections to file-rep.iaas.checkpoint.com:443</title>
      <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236322#M9845</link>
      <description>&lt;P&gt;Are you implying the super node also doesn't rely on the proxy for its Internet access?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 09:35:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236322#M9845</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-12-19T09:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: connections to file-rep.iaas.checkpoint.com:443</title>
      <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236323#M9846</link>
      <description>&lt;P&gt;Yes, the supernode has connectivity to the Cloud without the proxy. All these connections we can see on the proxy are only from the clients with installed EndPoint software.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 09:55:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236323#M9846</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-12-19T09:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: connections to file-rep.iaas.checkpoint.com:443</title>
      <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236411#M9852</link>
      <description>&lt;P&gt;Based on&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk171703" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk171703&lt;/A&gt;&amp;nbsp;this is expected behavior.&lt;BR /&gt;Specifically:&amp;nbsp;&lt;SPAN&gt;Currently, Super Node serves as an Anti-Malware signature proxy.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 18:24:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236411#M9852</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-19T18:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: connections to file-rep.iaas.checkpoint.com:443</title>
      <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236444#M9855</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We faced the same issue. These connections overloaded our proxy. I understand it is a normal behavior, according to TAC, &lt;SPAN&gt;Under the hood Anti-Malware E2 is part of Threat Emulation blade and cannot function independently. Therefore Threat Emulation as blade is installed, no matter how it is called Threat Emulation or File reputation.&lt;/SPAN&gt;&lt;BR clear="none" /&gt;. We found some options:&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Reduce the number of connections that agents do to those URL's. It needs to disable some fetures which reduces security. (File reputation, custom IoC, create exclusions for browsers cache folders)&lt;/LI&gt;
&lt;LI&gt;Use semi isolated enviaroments Super Node, all file-rep connections will go to Super Node. It does not work with authenticated proxy.&lt;/LI&gt;
&lt;LI&gt;Send these connections to a different proxy configuring&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Client Settings&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;General&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;Authenticated&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight2"&gt;Proxy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;. Again, it does not work with authenticated proxy! It should be fixed on E88.70.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;Just a tip. Make sure that all CheckPoint URL's are allowed on your proxy for endpoints. We found a couple endpoints without permissions to file-rep URL, and they went crazy, sent hundreds of attempts until we allowed the connection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 22:09:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236444#M9855</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2024-12-19T22:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: connections to file-rep.iaas.checkpoint.com:443</title>
      <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236459#M9857</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1920"&gt;@RS_Daniel&lt;/a&gt;&amp;nbsp;sounds good, we are not alone.&lt;/P&gt;
&lt;P&gt;Your second point is very interesting. We are using the Super Node, but all connections to file-rep...... are going through the normal proxy. It would be very helpful gettng these connection rid from the normal proxy. We don't use our proxy with authentication.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 07:11:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236459#M9857</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-12-20T07:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: connections to file-rep.iaas.checkpoint.com:443</title>
      <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236478#M9860</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;That option only worked after we enabled Semi Isolated mode on our tenant. A checkpoint team helped us enabling this feature on the server, and only then we were able to follow and enabled Semi Isolated super node configuration steps. Also i would try it with E88.50 or higher.&lt;/P&gt;
&lt;P&gt;You can check this training video shared by Bar Yassure:&lt;/P&gt;
&lt;P&gt;Learn more about this new capability:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://checkpoint.zoom.us/rec/share/dDYR-Mss-uE8-b0y8cO3bfi_k5prQ8GUmhMawQXcLrPCTu1WEAxkvLb5MwD9_kls.q0Io8sSo72lG5oEE" target="_blank" rel="nofollow noopener noreferrer"&gt;Technical Training&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(Passcode: 1Zmjq!ZA)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 12:54:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236478#M9860</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2024-12-20T12:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: connections to file-rep.iaas.checkpoint.com:443</title>
      <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236682#M9870</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1920"&gt;@RS_Daniel&lt;/a&gt;&amp;nbsp;as an information ... We could reduce the CPU utilization on the proxy significant by not logging the known URL. We have 500 clients and not logging these URL reduces CPU utilization form 80% =&amp;gt; 10% (4 cores active).&lt;/P&gt;
&lt;P&gt;######## small&amp;nbsp;ACL for squid-proxy #############&lt;/P&gt;
&lt;P&gt;acl nolog dstdomain \&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; file-rep.iaas.checkpoint.com&lt;/P&gt;
&lt;P&gt;access_log none nolog&lt;/P&gt;
&lt;P&gt;######## small&amp;nbsp;ACL for squid-proxy #############&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 13:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236682#M9870</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-12-23T13:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: connections to file-rep.iaas.checkpoint.com:443</title>
      <link>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236970#M9892</link>
      <description>&lt;P&gt;Good tip, thanks! will test it.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 18:49:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/connections-to-file-rep-iaas-checkpoint-com-443/m-p/236970#M9892</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2024-12-27T18:49:29Z</dc:date>
    </item>
  </channel>
</rss>

