<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Introducing On-device Network Protection (ONP) in Mobile</title>
    <link>https://community.checkpoint.com/t5/Mobile/Introducing-On-device-Network-Protection-ONP/m-p/41048#M228</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This week we are pleased to announce a new family of features, "On-device Network Protection (ONP)," now available for both Android and iOS devices.&lt;/P&gt;&lt;P&gt;ONP&amp;nbsp;enhances SandBlast Mobile's&amp;nbsp;advanced mobile threat protection and establishes a new mobile security paradigm to prevent emerging Gen V network attacks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2&gt;Main features introduced in ONP:&lt;/H2&gt;&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6;" width="100%"&gt;&lt;THEAD&gt;&lt;TR style="background-color: #efefef;"&gt;&lt;TH style="width: 10%;"&gt;Feature&lt;/TH&gt;&lt;TH style="width: 66.4355%;"&gt;Feature Description&lt;/TH&gt;&lt;TH style="width: 55.5645%;"&gt;Detailed Information for each feature&lt;/TH&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;Anti-Phishing&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category includes URLs that typically arrive in email or messaging apps and are established to steal information from users.&lt;/LI&gt;&lt;LI&gt;These sites falsely represent themselves as legitimate websites to obtain users' account credentials or credit card information that can be used for fraudulent or illegal purposes.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2904"&gt;New Capability for ONP: Anti-Phishing&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;Safe Browsing&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category includes URLs that may be reached during on-device browsing and are established to steal information from users or install drive-by malware.&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;These sites falsely represent themselves as legitimate websites to obtain users' account credentials or credit card information that can be used for fraudulent or illegal purposes.&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;These sites falsely represent themselves as legitimate websites to install malicious apps on the user's device to root/jailbreak the device, take command-and-control of the device, and steal on-device information.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2905"&gt;New Capability for ONP: Safe Browsing&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;Conditional Access&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category is a list of corporate IP addresses and/or FQDN hostnames&amp;nbsp;that the user's device cannot access while at high risk.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2908"&gt;New Capability for ONP: Conditional Access&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;Anti-Bot&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category includes URLs, IP addresses, or domain names that use bots (zombies), including command-and-control sites facilitating stealing on-device personal and corporate information, record video or audio, and/or install other malicous code.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2906"&gt;New Capability for ONP: Anti-Bot&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;URL Filtering&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category allows the administrator to prohibit devices from accessing particular URLs in a specific subject category, such as gambling, guns, and violence, etc.&lt;/LI&gt;&lt;LI&gt;This category also allows the administrator to blacklist domains from being able to accessed by the user's device&lt;SPAN&gt;&amp;nbsp;no matter the subject category or risk level of the device&lt;/SPAN&gt;.&lt;/LI&gt;&lt;LI&gt;In addition, this category also allows the administrator to whitelist domains that are always accessible to the user's device no matter the subject category or risk level of the device.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2907"&gt;New Capability for ONP: URL Filtering&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66993" class="image-2 jive-image" height="800" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66993_pastedImage_3.png" width="1283" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2&gt;Enabling and Configuring On-device Network Protection&lt;/H2&gt;&lt;OL&gt;&lt;LI&gt;Navigate to &lt;STRONG&gt;Settings &amp;gt; Policy Settings &amp;gt; On-device Network Protection&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Select the appropriate protection activation of "Always ON", "Always ON, allow user to suspend protection",&amp;nbsp;or "Turn ON when device is at HIGH risk".&lt;/LI&gt;&lt;LI&gt;Blocking connections to phishing, botnets, and spyware/malicious sites are on by default, but can be disabled if desired. &lt;BR /&gt;However, it is highly recommended that these settings are not disabled in order to provide the maximum level of protection.&lt;/LI&gt;&lt;LI&gt;See the individual features for additional information (listed in above table).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66994" alt="" class="image-3 jive-image j-img-original" src="/legacyfs/online/checkpoint/66994_6-25-2018 2-38-51 PM.png" /&gt;&lt;/P&gt;&lt;H2&gt;User Experience&lt;/H2&gt;&lt;P&gt;Once On-device Network Protection is enabled, the users will receive an in-app notification from SandBlast Mobile Protect to enable and install the VPN profile.&lt;/P&gt;&lt;P&gt;The VPN is a loopback VPN that allows all network traffic destination information to be inspected by SandBlast Mobile Protect app so that the configured ONP policies can be enforced at device.&lt;/P&gt;&lt;P&gt;The user must approve this install and follow any instructions to enable ONP on their devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;ONP Enablement - iOS&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;When the user is installing SandBlast Mobile Protect, and ONP is enabled in the Dashboard, the user will see a slightly different installation process.&lt;BR /&gt;&lt;/SPAN&gt;&lt;IMG alt="" class="image-7 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67263_ONP_iOS_Install-05.png" width="921" /&gt;&lt;BR /&gt;&lt;IMG alt="" class="image-8 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67264_ONP_iOS_Install-04.png" width="921" /&gt;&lt;/LI&gt;&lt;LI&gt;After installing and registering to SandBlast Mobile, the user can choose to enable "Notifications" and "Location".&lt;BR /&gt;&lt;IMG alt="" class="image-6 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67262_ONP_iOS_Install-03.png" width="919" /&gt;&lt;/LI&gt;&lt;LI&gt;The user must allow SandBlast Mobile Protect to install a loopback VPN profile. If the user doesn't permit this, their device will be at Medium Risk until they do so.&lt;BR /&gt;&lt;IMG alt="" class="image-5 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67261_ONP_iOS_Install-02.png" width="923" /&gt;&lt;/LI&gt;&lt;LI&gt;The user can then enable SMS Phishing protection by following the instructions.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Once the user has completed enabling permissions, the device will be scanned by SandBlast Mobile Protect.&lt;/SPAN&gt;&lt;IMG alt="" class="image-4 jive-image" height="301" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67260_ONP_iOS_Install-01.png" width="922" /&gt;&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;There are&amp;nbsp;new sections of the UI that will show the user that On-device Network Protection is enabled/disabled on their device.&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;By tapping "My Device", the user can see that Network Protection is "On".There are new sections of the UI that will show the user that On-device Network Protection is enabled on their device.&lt;BR /&gt;&lt;IMG alt="" class="image-19 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67275_ONP_iOS_Testing-07.png" width="423" /&gt;&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;&lt;SPAN&gt;By tapping "My Network", the user can see the number of URL that have been inspected over the last 24 hours, as well as the number of URLs blocked.&lt;BR /&gt;&lt;/SPAN&gt;&lt;IMG alt="" class="image-20 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67276_ONP_iOS_Testing-06.png" width="418" /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;H3 style="font-weight: bold;"&gt;ONP Enablement -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Android&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;When the user is installing SandBlast Mobile Protect, and ONP is enabled in the Dashboard, the user will see a slightly different installation process.&lt;BR /&gt;&lt;IMG alt="" class="image-9 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67265_ONP_Android_Install-04.png" width="980" /&gt;&lt;/LI&gt;&lt;LI&gt;After installing and registering to SandBlast Mobile, the user will need to enable "All all required permissions".&lt;/LI&gt;&lt;LI&gt;The user must allow SandBlast Mobile Protect to install a loopback VPN profile. If the user doesn't permit this, their device will be at Medium Risk until they do so.&lt;/LI&gt;&lt;LI&gt;The user can allow or disallow device location without penalty.&lt;BR /&gt;&lt;IMG alt="" class="image-10 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67266_ONP_Android_Install-03.png" width="978" /&gt;&lt;/LI&gt;&lt;LI&gt;The user can allow or disallow access to SMS messages without penalty.&lt;/LI&gt;&lt;LI&gt;The user must enable "Accessibility" for On-device Network Protection to work properly.&lt;BR /&gt;&lt;IMG alt="" class="image-11 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67267_ONP_Android_Install-02.png" width="980" /&gt;&lt;/LI&gt;&lt;LI&gt;Once the user has completed enabling permissions, the device will be scanned by SandBlast Mobile Protect.&lt;BR /&gt;&lt;IMG alt="" class="image-12 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67268_ONP_Android_Install-01.png" width="984" /&gt;&lt;/LI&gt;&lt;LI&gt;There are&amp;nbsp;new sections of the UI that will show the user that On-device Network Protection is enabled/disabled on their device.&lt;/LI&gt;&lt;LI&gt;By tapping "My Device", the user can see that Network Protection is "On".&lt;BR /&gt;&lt;IMG alt="" class="image-17 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67273_ONP_Android_Testing-07.png" width="438" /&gt;&lt;/LI&gt;&lt;LI&gt;By tapping "My Network", the user can see the number of URL that have been inspected over the last 24 hours, as well as the number of URLs blocked.&lt;BR /&gt;&lt;IMG alt="" class="image-21 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67277_ONP_Android_Testing-06.png" width="443" /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;H2&gt;Suspending Network Protection&lt;/H2&gt;&lt;P&gt;If the administrator has configured On-device Network Protection for "Always ON, allow user to suspend protection", then the user's can suspend ONP from a set time of 5 minutes, 30 minutes, or 2 hours.&lt;/P&gt;&lt;P&gt;This is often useful in a BYOD environment that will allow user's to suspend ONP protections.&lt;/P&gt;&lt;H3&gt;iOS User Experience&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;Tapping the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;More&amp;nbsp;&lt;/EM&gt;menu, the user can select "Suspend Network Protection".&lt;/LI&gt;&lt;LI&gt;Select the amount of time to suspend, tapping "OK".&lt;/LI&gt;&lt;LI&gt;The UI will show that Network Protection has been suspended and the time remaining.&lt;BR /&gt;&lt;IMG alt="" class="image-13 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67269_ONP_iOS_Testing-05.png" width="910" /&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;If the user wishes to cancel the suspension, the user can tap the&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;More&lt;/EM&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;menu again, and select "Activate Network Protection".&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;IMG alt="" class="image-14 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67270_ONP_iOS_Testing-04.png" width="663" /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;Android User Experience&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;Tapping the &lt;EM&gt;More&amp;nbsp;&lt;/EM&gt;menu, the user can select "Suspend Network Protection".&lt;/LI&gt;&lt;LI&gt;Select the amount of time to suspend, tapping "OK".&lt;/LI&gt;&lt;LI&gt;The UI will show that Network Protection has been suspended and the time remaining.&lt;BR /&gt;&lt;IMG alt="" class="image-15 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67271_ONP_Android_Testing-05.png" width="972" /&gt;&lt;/LI&gt;&lt;LI&gt;If the user wishes to cancel the suspension, the user can tap the &lt;EM&gt;More&lt;/EM&gt; menu again, and select "Activate Network Protection".&amp;nbsp;&lt;BR /&gt;&lt;IMG alt="" class="image-16 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67272_ONP_Android_Testing-04.png" width="700" /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 May 2018 20:13:18 GMT</pubDate>
    <dc:creator>Pamela_S__Lee</dc:creator>
    <dc:date>2018-05-07T20:13:18Z</dc:date>
    <item>
      <title>Introducing On-device Network Protection (ONP)</title>
      <link>https://community.checkpoint.com/t5/Mobile/Introducing-On-device-Network-Protection-ONP/m-p/41048#M228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This week we are pleased to announce a new family of features, "On-device Network Protection (ONP)," now available for both Android and iOS devices.&lt;/P&gt;&lt;P&gt;ONP&amp;nbsp;enhances SandBlast Mobile's&amp;nbsp;advanced mobile threat protection and establishes a new mobile security paradigm to prevent emerging Gen V network attacks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2&gt;Main features introduced in ONP:&lt;/H2&gt;&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6;" width="100%"&gt;&lt;THEAD&gt;&lt;TR style="background-color: #efefef;"&gt;&lt;TH style="width: 10%;"&gt;Feature&lt;/TH&gt;&lt;TH style="width: 66.4355%;"&gt;Feature Description&lt;/TH&gt;&lt;TH style="width: 55.5645%;"&gt;Detailed Information for each feature&lt;/TH&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;Anti-Phishing&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category includes URLs that typically arrive in email or messaging apps and are established to steal information from users.&lt;/LI&gt;&lt;LI&gt;These sites falsely represent themselves as legitimate websites to obtain users' account credentials or credit card information that can be used for fraudulent or illegal purposes.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2904"&gt;New Capability for ONP: Anti-Phishing&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;Safe Browsing&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category includes URLs that may be reached during on-device browsing and are established to steal information from users or install drive-by malware.&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;These sites falsely represent themselves as legitimate websites to obtain users' account credentials or credit card information that can be used for fraudulent or illegal purposes.&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;These sites falsely represent themselves as legitimate websites to install malicious apps on the user's device to root/jailbreak the device, take command-and-control of the device, and steal on-device information.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2905"&gt;New Capability for ONP: Safe Browsing&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;Conditional Access&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category is a list of corporate IP addresses and/or FQDN hostnames&amp;nbsp;that the user's device cannot access while at high risk.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2908"&gt;New Capability for ONP: Conditional Access&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;Anti-Bot&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category includes URLs, IP addresses, or domain names that use bots (zombies), including command-and-control sites facilitating stealing on-device personal and corporate information, record video or audio, and/or install other malicous code.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2906"&gt;New Capability for ONP: Anti-Bot&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 10%;"&gt;&lt;STRONG&gt;URL Filtering&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="width: 66.4355%;"&gt;&lt;UL&gt;&lt;LI&gt;This category allows the administrator to prohibit devices from accessing particular URLs in a specific subject category, such as gambling, guns, and violence, etc.&lt;/LI&gt;&lt;LI&gt;This category also allows the administrator to blacklist domains from being able to accessed by the user's device&lt;SPAN&gt;&amp;nbsp;no matter the subject category or risk level of the device&lt;/SPAN&gt;.&lt;/LI&gt;&lt;LI&gt;In addition, this category also allows the administrator to whitelist domains that are always accessible to the user's device no matter the subject category or risk level of the device.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD style="width: 55.5645%;"&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2907"&gt;New Capability for ONP: URL Filtering&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66993" class="image-2 jive-image" height="800" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66993_pastedImage_3.png" width="1283" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2&gt;Enabling and Configuring On-device Network Protection&lt;/H2&gt;&lt;OL&gt;&lt;LI&gt;Navigate to &lt;STRONG&gt;Settings &amp;gt; Policy Settings &amp;gt; On-device Network Protection&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Select the appropriate protection activation of "Always ON", "Always ON, allow user to suspend protection",&amp;nbsp;or "Turn ON when device is at HIGH risk".&lt;/LI&gt;&lt;LI&gt;Blocking connections to phishing, botnets, and spyware/malicious sites are on by default, but can be disabled if desired. &lt;BR /&gt;However, it is highly recommended that these settings are not disabled in order to provide the maximum level of protection.&lt;/LI&gt;&lt;LI&gt;See the individual features for additional information (listed in above table).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66994" alt="" class="image-3 jive-image j-img-original" src="/legacyfs/online/checkpoint/66994_6-25-2018 2-38-51 PM.png" /&gt;&lt;/P&gt;&lt;H2&gt;User Experience&lt;/H2&gt;&lt;P&gt;Once On-device Network Protection is enabled, the users will receive an in-app notification from SandBlast Mobile Protect to enable and install the VPN profile.&lt;/P&gt;&lt;P&gt;The VPN is a loopback VPN that allows all network traffic destination information to be inspected by SandBlast Mobile Protect app so that the configured ONP policies can be enforced at device.&lt;/P&gt;&lt;P&gt;The user must approve this install and follow any instructions to enable ONP on their devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;ONP Enablement - iOS&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;When the user is installing SandBlast Mobile Protect, and ONP is enabled in the Dashboard, the user will see a slightly different installation process.&lt;BR /&gt;&lt;/SPAN&gt;&lt;IMG alt="" class="image-7 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67263_ONP_iOS_Install-05.png" width="921" /&gt;&lt;BR /&gt;&lt;IMG alt="" class="image-8 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67264_ONP_iOS_Install-04.png" width="921" /&gt;&lt;/LI&gt;&lt;LI&gt;After installing and registering to SandBlast Mobile, the user can choose to enable "Notifications" and "Location".&lt;BR /&gt;&lt;IMG alt="" class="image-6 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67262_ONP_iOS_Install-03.png" width="919" /&gt;&lt;/LI&gt;&lt;LI&gt;The user must allow SandBlast Mobile Protect to install a loopback VPN profile. If the user doesn't permit this, their device will be at Medium Risk until they do so.&lt;BR /&gt;&lt;IMG alt="" class="image-5 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67261_ONP_iOS_Install-02.png" width="923" /&gt;&lt;/LI&gt;&lt;LI&gt;The user can then enable SMS Phishing protection by following the instructions.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Once the user has completed enabling permissions, the device will be scanned by SandBlast Mobile Protect.&lt;/SPAN&gt;&lt;IMG alt="" class="image-4 jive-image" height="301" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67260_ONP_iOS_Install-01.png" width="922" /&gt;&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;There are&amp;nbsp;new sections of the UI that will show the user that On-device Network Protection is enabled/disabled on their device.&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;By tapping "My Device", the user can see that Network Protection is "On".There are new sections of the UI that will show the user that On-device Network Protection is enabled on their device.&lt;BR /&gt;&lt;IMG alt="" class="image-19 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67275_ONP_iOS_Testing-07.png" width="423" /&gt;&lt;/LI&gt;&lt;LI style="margin: 0.2em 0px;"&gt;&lt;SPAN&gt;By tapping "My Network", the user can see the number of URL that have been inspected over the last 24 hours, as well as the number of URLs blocked.&lt;BR /&gt;&lt;/SPAN&gt;&lt;IMG alt="" class="image-20 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67276_ONP_iOS_Testing-06.png" width="418" /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;H3 style="font-weight: bold;"&gt;ONP Enablement -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Android&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;When the user is installing SandBlast Mobile Protect, and ONP is enabled in the Dashboard, the user will see a slightly different installation process.&lt;BR /&gt;&lt;IMG alt="" class="image-9 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67265_ONP_Android_Install-04.png" width="980" /&gt;&lt;/LI&gt;&lt;LI&gt;After installing and registering to SandBlast Mobile, the user will need to enable "All all required permissions".&lt;/LI&gt;&lt;LI&gt;The user must allow SandBlast Mobile Protect to install a loopback VPN profile. If the user doesn't permit this, their device will be at Medium Risk until they do so.&lt;/LI&gt;&lt;LI&gt;The user can allow or disallow device location without penalty.&lt;BR /&gt;&lt;IMG alt="" class="image-10 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67266_ONP_Android_Install-03.png" width="978" /&gt;&lt;/LI&gt;&lt;LI&gt;The user can allow or disallow access to SMS messages without penalty.&lt;/LI&gt;&lt;LI&gt;The user must enable "Accessibility" for On-device Network Protection to work properly.&lt;BR /&gt;&lt;IMG alt="" class="image-11 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67267_ONP_Android_Install-02.png" width="980" /&gt;&lt;/LI&gt;&lt;LI&gt;Once the user has completed enabling permissions, the device will be scanned by SandBlast Mobile Protect.&lt;BR /&gt;&lt;IMG alt="" class="image-12 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67268_ONP_Android_Install-01.png" width="984" /&gt;&lt;/LI&gt;&lt;LI&gt;There are&amp;nbsp;new sections of the UI that will show the user that On-device Network Protection is enabled/disabled on their device.&lt;/LI&gt;&lt;LI&gt;By tapping "My Device", the user can see that Network Protection is "On".&lt;BR /&gt;&lt;IMG alt="" class="image-17 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67273_ONP_Android_Testing-07.png" width="438" /&gt;&lt;/LI&gt;&lt;LI&gt;By tapping "My Network", the user can see the number of URL that have been inspected over the last 24 hours, as well as the number of URLs blocked.&lt;BR /&gt;&lt;IMG alt="" class="image-21 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67277_ONP_Android_Testing-06.png" width="443" /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;H2&gt;Suspending Network Protection&lt;/H2&gt;&lt;P&gt;If the administrator has configured On-device Network Protection for "Always ON, allow user to suspend protection", then the user's can suspend ONP from a set time of 5 minutes, 30 minutes, or 2 hours.&lt;/P&gt;&lt;P&gt;This is often useful in a BYOD environment that will allow user's to suspend ONP protections.&lt;/P&gt;&lt;H3&gt;iOS User Experience&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;Tapping the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;More&amp;nbsp;&lt;/EM&gt;menu, the user can select "Suspend Network Protection".&lt;/LI&gt;&lt;LI&gt;Select the amount of time to suspend, tapping "OK".&lt;/LI&gt;&lt;LI&gt;The UI will show that Network Protection has been suspended and the time remaining.&lt;BR /&gt;&lt;IMG alt="" class="image-13 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67269_ONP_iOS_Testing-05.png" width="910" /&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;If the user wishes to cancel the suspension, the user can tap the&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;More&lt;/EM&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;menu again, and select "Activate Network Protection".&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;IMG alt="" class="image-14 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67270_ONP_iOS_Testing-04.png" width="663" /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;Android User Experience&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;Tapping the &lt;EM&gt;More&amp;nbsp;&lt;/EM&gt;menu, the user can select "Suspend Network Protection".&lt;/LI&gt;&lt;LI&gt;Select the amount of time to suspend, tapping "OK".&lt;/LI&gt;&lt;LI&gt;The UI will show that Network Protection has been suspended and the time remaining.&lt;BR /&gt;&lt;IMG alt="" class="image-15 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67271_ONP_Android_Testing-05.png" width="972" /&gt;&lt;/LI&gt;&lt;LI&gt;If the user wishes to cancel the suspension, the user can tap the &lt;EM&gt;More&lt;/EM&gt; menu again, and select "Activate Network Protection".&amp;nbsp;&lt;BR /&gt;&lt;IMG alt="" class="image-16 jive-image" height="300" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67272_ONP_Android_Testing-04.png" width="700" /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 May 2018 20:13:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Introducing-On-device-Network-Protection-ONP/m-p/41048#M228</guid>
      <dc:creator>Pamela_S__Lee</dc:creator>
      <dc:date>2018-05-07T20:13:18Z</dc:date>
    </item>
  </channel>
</rss>

