<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: disc encryption in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224384#M37374</link>
    <description>&lt;P&gt;I would still double check with TAC.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2024 13:15:41 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-08-23T13:15:41Z</dc:date>
    <item>
      <title>disc encryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224244#M37353</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;tried to find out some information regarding disc encryption. Especially on CheckPoint appliances with e.g. R81.10.&lt;/P&gt;
&lt;P&gt;It looks like that there is no encryption by default. Correct?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any recommendation / best practise?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Checkmate ChatGPT provides infos to&amp;nbsp;&amp;nbsp;ATRG: Full Disk Encryption (FDE) which and then refers to:&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;For detailed instructions and best practices, you can refer to the&amp;nbsp;&lt;A title="https://community.checkpoint.com" href="https://community.checkpoint.com/" target="_blank" rel="nofollow noopener"&gt;https://community.checkpoint.com&lt;/A&gt;.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, FDE seems to be for Client PC (win/mac) and not for GAiA&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 09:29:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224244#M37353</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2024-08-22T09:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: disc encryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224256#M37354</link>
      <description>&lt;P&gt;Thats my understanding as well. I never heard of disk encryption for actual appliances, only endpoint.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;Maybe someone can confirm if Im mistaken though.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/SmartEndpoint_OLH/EN/Topics-EPSG/FDE-CPEncryptionPolicy-configuring.htm?TocPath=Full%20Disk%20Encryption%7CCheck%20Point%20Full%20Disk%20Encryption%7CConfiguring%20a%20Check%20Point%20Full%20Disk%20Encryption%20Policy%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/SmartEndpoint_OLH/EN/Topics-EPSG/FDE-CPEncryptionPolicy-configuring.htm?TocPath=Full%20Disk%20Encryption%7CCheck%20Point%20Full%20Disk%20Encryption%7CConfiguring%20a%20Check%20Point%20Full%20Disk%20Encryption%20Policy%7C_____0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 12:26:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224256#M37354</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-22T12:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: disc encryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224310#M37357</link>
      <description>&lt;P&gt;Reposting an answer from one of my &lt;SPAN&gt;colleagues:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check Point Gaia is a hardened OS and intended for access by qualified and trained administrators only using strong authentication methods. They should also be installed in physically secure locations that are accessible only to trusted and authorized employees (R82 adds 2FA in Gaia)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally all Check Point management traffic is strongly secured by SIC, providing confidentiality, integrity and MUTUAL authentication to management protocols over the network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assuming that these mitigating controls have been followed, the likelihood of malicious tampering is all but eliminated. This makes technical controls, like disk encryption, risky as such technologies could make things like RMA, troubleshooting, etc. much more difficult and time-consuming.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 16:47:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224310#M37357</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-08-22T16:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: disc encryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224314#M37358</link>
      <description>&lt;P&gt;Thanks for that explanation Tal.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 16:46:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224314#M37358</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-22T16:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: disc encryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224362#M37368</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Reposting an answer from one of my &lt;SPAN&gt;colleagues:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check Point Gaia is a hardened OS and intended for access by qualified and trained administrators only using strong authentication methods.&lt;/P&gt;
&lt;P&gt;..&lt;/P&gt;
&lt;P&gt;Assuming that these mitigating controls have been followed, the likelihood of malicious tampering is all but eliminated. This makes technical controls, like disk encryption, risky as such technologies could make things like RMA, troubleshooting, etc. much more difficult and time-consuming.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Bingo, that is exactly the point.&lt;/P&gt;
&lt;P&gt;Even if you have a strong authentication (TACACS+; RADIUS,AD) to GAIA OS.&lt;/P&gt;
&lt;P&gt;I assume that you still need some kind of an emergency user (if above methods fail; connectivity issue) or expert password,&amp;nbsp; GRUB password.&lt;/P&gt;
&lt;P&gt;Doing now an RMA of a harddisk, config and password/hashes can be read. (Please correct me if I'm wrong)&lt;/P&gt;
&lt;P&gt;RAID1, RAID6 does not help in this case&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 08:57:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224362#M37368</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2024-08-23T08:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: disc encryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224368#M37370</link>
      <description>&lt;P&gt;In the case of an RMA you could atleast in the past retain the disk and dispose of this securely.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/uc/htmls/pricelist/HardDriveRMA.html" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/uc/htmls/pricelist/HardDriveRMA.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 10:49:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224368#M37370</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-23T10:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: disc encryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224369#M37371</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks for info.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Obviously not valid for 6xxx/7xxx/9xxx series even for Diamond Customers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: Only the following appliances are applicable for the HDD Retention Service: Smart-1 series (Smart -1 225, 3050 &amp;amp; 3150), 5900 appliance, Connectra 9070 (only),12000 series, 13000 series, 15000 series, 21400 series, 21600 series, 21700 series, 21800 series, 23000 series, TE1000x, and TE2000x series, IAS, IP Appliances (where applicable).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nevertheless, thanks for info/input&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 10:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224369#M37371</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2024-08-23T10:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: disc encryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224383#M37373</link>
      <description>&lt;P&gt;We do not currently implement FDE or similar technology on Quantum appliances.&lt;BR /&gt;Your best bet is to work with your local Check Point office on an RFE and/or an approved procedure for handling RMAs on sealed disk units.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 13:15:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224383#M37373</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-23T13:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: disc encryption</title>
      <link>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224384#M37374</link>
      <description>&lt;P&gt;I would still double check with TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 13:15:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/disc-encryption/m-p/224384#M37374</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-23T13:15:41Z</dc:date>
    </item>
  </channel>
</rss>

