<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DLP Gateway for G Suite relay in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35223#M7420</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DLP for SMTP definitely requires a relay of some sort.&lt;/P&gt;&lt;P&gt;In fact, the recommended configuration is to have an internal mail server and a separate relay in the DMZ&lt;/P&gt;&lt;P&gt;The relay can be internal, but this is not recommended.&lt;/P&gt;&lt;P&gt;Both configurations are discussed here:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_DataLossPrevention_AdminGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_DataLossPrevention_AdminGuide/html_frameset.htm"&gt;Data Loss Prevention R80.10 (Part of Check Point Infinity)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 24 Feb 2019 02:33:47 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-02-24T02:33:47Z</dc:date>
    <item>
      <title>DLP Gateway for G Suite relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35222#M7419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for a suggestion on the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Requirement&lt;/STRONG&gt;:&lt;BR /&gt;DLP policy enforcement for outbound SMTP Traffic to G Suite mail relay located on internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Setup&lt;/STRONG&gt;:&lt;BR /&gt;R80.10 Distributed setup&lt;BR /&gt;HTTPS inspection &lt;STRONG&gt;not&lt;/STRONG&gt; enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Description&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;The Mail Relay is located at mail-relay.google.com as customer has a G Suite setup.&lt;BR /&gt;We have enabled SMTP protocol under DLP configuration but could not set the mail server as the relay server IP is dynamic in nature.&lt;BR /&gt;Not able to add the FQDN address to Mail Server object.&lt;/P&gt;&lt;P&gt;DLP policy is currently not enforced with this configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to achieve this requirement without an internal mail server?&lt;BR /&gt;Or should the customer setup an on premise mail relay to enforce DLP policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the attachment for the required topology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Arun Kumar S&lt;BR /&gt;Security Engineer&lt;BR /&gt;QOS Technology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/45458"&gt;Prabulingam N&lt;/A&gt;‌&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Feb 2019 16:06:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35222#M7419</guid>
      <dc:creator>Arun_Kumar_S</dc:creator>
      <dc:date>2019-02-23T16:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: DLP Gateway for G Suite relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35223#M7420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DLP for SMTP definitely requires a relay of some sort.&lt;/P&gt;&lt;P&gt;In fact, the recommended configuration is to have an internal mail server and a separate relay in the DMZ&lt;/P&gt;&lt;P&gt;The relay can be internal, but this is not recommended.&lt;/P&gt;&lt;P&gt;Both configurations are discussed here:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_DataLossPrevention_AdminGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_DataLossPrevention_AdminGuide/html_frameset.htm"&gt;Data Loss Prevention R80.10 (Part of Check Point Infinity)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Feb 2019 02:33:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35223#M7420</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-24T02:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: DLP Gateway for G Suite relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35224#M7421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now, customer doesn't have a mail server nor a mail relay located on-premise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The mail relay is on google cloud and it relays the received mails to the mail server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the document, it is required to have an internal mail relay and/or an internal mail server. (Not sure if mail server is mandatory to be internal.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, the requirement that I mentioned is not possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Feb 2019 06:55:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35224#M7421</guid>
      <dc:creator>Arun_Kumar_S</dc:creator>
      <dc:date>2019-02-24T06:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: DLP Gateway for G Suite relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35225#M7422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Theoretically the mail relay/server could be one in the same server, but it should be on-premise to use the DLP blade on an on-premise security gateway.&lt;/P&gt;&lt;P&gt;If you're wanting to do DLP with G-Suite, you should be looking into CloudGuard SaaS as that integrates more directly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Feb 2019 13:22:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35225#M7422</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-24T13:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: DLP Gateway for G Suite relay</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35226#M7423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Feb 2019 13:25:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DLP-Gateway-for-G-Suite-relay/m-p/35226#M7423</guid>
      <dc:creator>Arun_Kumar_S</dc:creator>
      <dc:date>2019-02-24T13:25:36Z</dc:date>
    </item>
  </channel>
</rss>

