<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloudguard EDGE vs IaaS on Cisco ENCS platform for SD-WAN firewall security in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cloudguard-EDGE-vs-IaaS-on-Cisco-ENCS-platform-for-SD-WAN/m-p/96087#M63</link>
    <description>&lt;P&gt;At least the way I read the download SK, you should be able to use the R80.30 image that says it’s for ENCS.&lt;BR /&gt;I would not use a standard R80.40 ISO here as there are probably a few differences in drivers/packaging that would make it not work.&lt;/P&gt;
&lt;P&gt;We should have an R80.20 version of CloudGuard VNF soon as well.&lt;/P&gt;</description>
    <pubDate>Sat, 05 Sep 2020 03:44:22 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-09-05T03:44:22Z</dc:date>
    <item>
      <title>Cloudguard EDGE vs IaaS on Cisco ENCS platform for SD-WAN firewall security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cloudguard-EDGE-vs-IaaS-on-Cisco-ENCS-platform-for-SD-WAN/m-p/96071#M62</link>
      <description>&lt;P&gt;Hello --&amp;nbsp; Checkpoint customer looking into Cisco 5000 Enterprise Network Compute System (ENCS) for SD-WAN platform.&lt;/P&gt;&lt;P&gt;Customer has been running R80.30 and looking into upgrades to R80.40.&amp;nbsp;&amp;nbsp; They are hesitant to consider EDGE for ENCS because current available image based on R77.20.xx.&lt;/P&gt;&lt;P&gt;Can they run Cloudguard IaaS in place of the EDGE VNF image for SD-WAN security on 5000-series ENCS platform?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I understand there is a licensing and cost difference between the two.&lt;/P&gt;&lt;P&gt;Thanks-GA&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cloudguard IaaS is "mostly full GAIA" and R80.30+&lt;/P&gt;&lt;P&gt;Cloudguard VNF/EDGE is embedded GAIA and R77.20x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;reference links below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ENCS-vmdeployment1.png" style="width: 875px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7929i68FC59A6D9D5D0BA/image-size/large?v=v2&amp;amp;px=999" role="button" title="ENCS-vmdeployment1.png" alt="ENCS-vmdeployment1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The R80.30 GAIA build for ENCS is listed as "Cloudguard for private cloud".&lt;/P&gt;&lt;P&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk158292" target="_blank" rel="noopener"&gt;http://supportcontent.checkpoint.com/solutions?id=sk158292&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The R77.30 VNF build for ENCS listed as "Cloudguard EDGE".&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166421" target="_blank" rel="noopener"&gt;http://supportcontent.checkpoint.com/solutions?id=sk166421&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SD-WAN integration guides &lt;A href="https://community.checkpoint.com/t5/Secure-Cloud-Access-SD-WAN/Check-Point-integration-guides-with-SD-WAN-vendors/m-p/85373" target="_blank" rel="noopener"&gt;HERE&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 18:48:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cloudguard-EDGE-vs-IaaS-on-Cisco-ENCS-platform-for-SD-WAN/m-p/96071#M62</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2020-09-04T18:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard EDGE vs IaaS on Cisco ENCS platform for SD-WAN firewall security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cloudguard-EDGE-vs-IaaS-on-Cisco-ENCS-platform-for-SD-WAN/m-p/96087#M63</link>
      <description>&lt;P&gt;At least the way I read the download SK, you should be able to use the R80.30 image that says it’s for ENCS.&lt;BR /&gt;I would not use a standard R80.40 ISO here as there are probably a few differences in drivers/packaging that would make it not work.&lt;/P&gt;
&lt;P&gt;We should have an R80.20 version of CloudGuard VNF soon as well.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2020 03:44:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cloudguard-EDGE-vs-IaaS-on-Cisco-ENCS-platform-for-SD-WAN/m-p/96087#M63</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-05T03:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard EDGE vs IaaS on Cisco ENCS platform for SD-WAN firewall security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cloudguard-EDGE-vs-IaaS-on-Cisco-ENCS-platform-for-SD-WAN/m-p/96381#M64</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;.&amp;nbsp; &amp;nbsp; thanks for reply&amp;nbsp; and insight.&amp;nbsp;&lt;/P&gt;&lt;P&gt;while customer (and myself) feel that R77.20.x embedded GAIA is ancient, the current R80.20 embedded GAIA release is becoming somewhat "old" as well.&amp;nbsp; &amp;nbsp; &amp;nbsp;I suggest the embedded GAIA releases (for appliances and VNF) should be updated to more recent GAIA release sooner vs later (example:&amp;nbsp; straight to R80.40).&lt;/P&gt;&lt;P&gt;The primary gateway focus for customer are (a) layers, and (b) HTTPS decrypt enhancements with more recent GAIA builds.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both the embedded GAIA and Cloudguard releases trail the primary GAIA release cycles.&amp;nbsp; &amp;nbsp; Customer has encountered numerous "defects" and issues requiring hotfixes (or waiting for fix to arrive in JHA/jumbo).&amp;nbsp; &amp;nbsp;they are concerned about using a "special" GAIA release (embedded or cloudguard) that is not updated frequently and does not have obvious any way to apply hotfixes, etc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 16:13:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cloudguard-EDGE-vs-IaaS-on-Cisco-ENCS-platform-for-SD-WAN/m-p/96381#M64</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2020-09-09T16:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard EDGE vs IaaS on Cisco ENCS platform for SD-WAN firewall security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cloudguard-EDGE-vs-IaaS-on-Cisco-ENCS-platform-for-SD-WAN/m-p/96407#M65</link>
      <description>&lt;P&gt;The logic behind using our SMB code for VNF is that it operates in a reduced memory/CPU footprint, which is appropriate in some SD-WAN devices.&lt;BR /&gt;In general, while the version is nominally R80.20, features from later releases are sometimes backported into the current SMB release.&lt;BR /&gt;I wouldn't get hung up on the precise version here, though pointing out missing features is fair.&lt;/P&gt;
&lt;P&gt;My understanding on the two issues you bring up are: Layers are supported (when managed with regular Check Point Security Management), and that SNI support should be there.&lt;/P&gt;
&lt;P&gt;I presume we will create a version of SMB/VNF based on a newer version of maintrain code (probably in the R81 line), but don't know the precise timeline.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 19:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cloudguard-EDGE-vs-IaaS-on-Cisco-ENCS-platform-for-SD-WAN/m-p/96407#M65</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-09T19:40:29Z</dc:date>
    </item>
  </channel>
</rss>

