<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Check Point's New SASE Solution Powered by Odo: Video, Slides, and Q&amp;amp;A in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-s-New-SASE-Solution-Powered-by-Odo-Video-Slides-and/m-p/98456#M68</link>
    <description>&lt;P&gt;Materials presented available to CheckMates members:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/t5/Member-Exclusive-Content/Check-Point-s-New-SASE-Solution-Powered-by-Odo-Video-and-Slides/m-p/98455#M454" target="_self"&gt;Video Recording&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/member-exclusives/454/1/Check%20Point%20SASE%20remote%20access%20with%20Odo%2007102020.pdf" target="_self"&gt;Slides&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Selected Q&amp;amp;A Below:&lt;/P&gt;
&lt;H3&gt;How Can We Get a Demo?&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://pages.checkpoint.com/corporate-access-demo.html" target="_self"&gt;Request a demo here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Are there any Endpoint Compliance checks done as part of Odo?&lt;/H3&gt;
&lt;P&gt;Currently, no, but this is a top-priority for us that is in short term roadmap. It will be similar to our existing Endpoint Security on Demand for Mobile Access Blade but a different implementation.&lt;/P&gt;
&lt;H3&gt;Can users access shared drives with Odo?&lt;/H3&gt;
&lt;P&gt;Not currently. This is something Mobile Access Blade supports today.&lt;/P&gt;
&lt;H3&gt;Will this be integrated with CloudGuard Connect?&lt;/H3&gt;
&lt;P&gt;Initially, no, but this is planned for early next year.&lt;/P&gt;
&lt;H3&gt;What Identity Providers are supported?&lt;/H3&gt;
&lt;P&gt;Okta, Duo, Azure AD, onelogin, Ping.&lt;/P&gt;
&lt;H3&gt;Is Multiple Concurrent IDPs supported?&lt;/H3&gt;
&lt;P&gt;Not currently, but the "dual-mode" of several IDPs, plus IDP and Local Directory is on the short-term roadmap.&lt;/P&gt;
&lt;H3&gt;Is Local (On-prem) AD supported?&lt;/H3&gt;
&lt;P&gt;Yes, assuming the AD is accessible from the Docker agent installed on-premise.&lt;/P&gt;
&lt;H3&gt;Do I need to allow any inbound access on my perimeter gateways?&lt;/H3&gt;
&lt;P&gt;No, a Docker agent installed on-premise will initiate an outbound HTTPS connection to the Check Point cloud and will proxy all authorized traffic inbound to the datacenter.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;How are applications that require port ranges/dynamic ports supported?&lt;/H3&gt;
&lt;P&gt;We support applications that tunnel over web, RDP, SQL, or SSH (including SSH tunneling). We do not support arbitrary applications.&lt;/P&gt;
&lt;H3&gt;How much latency is added to application access?&lt;/H3&gt;
&lt;P&gt;It is similar to an nginx reverse proxy, which is minimal. Our data plane is located in many different regions to reduce latency.&lt;/P&gt;
&lt;H3&gt;Will the gateway decrypt the HTTPS connection from the browser and re-establish another HTTPS connection to the connector?&lt;/H3&gt;
&lt;P class="p1"&gt;Yes. Since the solution is DNS based we own our own certificate and will send it once opened to the server side (trusted proxy).&lt;/P&gt;
&lt;H3 class="p1"&gt;Where is the user activity video stored?&lt;/H3&gt;
&lt;P&gt;In AWS Encrypted File Store. Access to this is limited to admins and is stored by default for 30 days.&lt;/P&gt;
&lt;H3&gt;Are the user activity recordings indexed?&lt;/H3&gt;
&lt;P&gt;RDP is not indexed, SSH indexing is on the roadmap.&lt;/P&gt;
&lt;H3&gt;Can you explain the end-to-end connection flow?&lt;/H3&gt;
&lt;P&gt;The user authenticates to the controller (hosted in the cloud), which returns a list of available applications. Any authorized access to these applications is routed through the gateway to the on-premise Docker agent.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Is this a replacement for Mobile Access Blade?&lt;/H3&gt;
&lt;P&gt;It is a complimentary solution to Mobile Access Blade.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;What SaaS apps are supported?&lt;/H3&gt;
&lt;P&gt;Any web-based SaaS app is supported.&lt;/P&gt;
&lt;H3&gt;Will VDI be supported for both VMware and Citrix?&lt;/H3&gt;
&lt;P&gt;Depends on the use case. We generally recommend using RDP.&lt;/P&gt;
&lt;H3&gt;Is this integrated with SmartConsole and/or Infinity Portal?&lt;/H3&gt;
&lt;P&gt;No, this is not integrated with SmartConsole. We plan to have this as part of Infinity Portal by the end of 2020.&lt;/P&gt;
&lt;H3&gt;Can you access SmartConsole via Odo?&lt;/H3&gt;
&lt;P&gt;Only via a machine accessible with RDP. Once a web-based SmartConsole is available (planned in the R81 timeframe), this should be accessible via Odo.&lt;/P&gt;
&lt;H3&gt;Can RDP Copy/Paste be blocked when connected via Clientless mode?&lt;/H3&gt;
&lt;P&gt;Yes, we can also block download of files per configuration.&lt;/P&gt;
&lt;H3&gt;Is VNC supported?&lt;/H3&gt;
&lt;P&gt;Not currently. If this is of interest, please contact your local Check Point office.&lt;/P&gt;
&lt;H3&gt;Does this replace VPN?&lt;/H3&gt;
&lt;P class="p1"&gt;VPN replacement is a possible use case for Odo, although Odo does not fully replace VPN. Odo only supports Web, SSH, RDP and some database access. As such, it is not a full replacement for Mobile Access Blade, Remote Access VPN, or Site-to-Site VPN.&lt;/P&gt;
&lt;H3 class="p1"&gt;If applications are defined in an existing IdP, what is the process for moving them to Odo?&lt;/H3&gt;
&lt;P class="p1"&gt;The app URL will change as we provide a new FQDN for each app.&lt;/P&gt;
&lt;H3 class="p1"&gt;Will a DLP solution be integrated?&lt;/H3&gt;
&lt;P&gt;This is planned for next year as part of CloudGuard Connect.&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Oct 2020 16:55:35 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-10-07T16:55:35Z</dc:date>
    <item>
      <title>Check Point's New SASE Solution Powered by Odo: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-s-New-SASE-Solution-Powered-by-Odo-Video-Slides-and/m-p/98456#M68</link>
      <description>&lt;P&gt;Materials presented available to CheckMates members:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/t5/Member-Exclusive-Content/Check-Point-s-New-SASE-Solution-Powered-by-Odo-Video-and-Slides/m-p/98455#M454" target="_self"&gt;Video Recording&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/member-exclusives/454/1/Check%20Point%20SASE%20remote%20access%20with%20Odo%2007102020.pdf" target="_self"&gt;Slides&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Selected Q&amp;amp;A Below:&lt;/P&gt;
&lt;H3&gt;How Can We Get a Demo?&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://pages.checkpoint.com/corporate-access-demo.html" target="_self"&gt;Request a demo here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Are there any Endpoint Compliance checks done as part of Odo?&lt;/H3&gt;
&lt;P&gt;Currently, no, but this is a top-priority for us that is in short term roadmap. It will be similar to our existing Endpoint Security on Demand for Mobile Access Blade but a different implementation.&lt;/P&gt;
&lt;H3&gt;Can users access shared drives with Odo?&lt;/H3&gt;
&lt;P&gt;Not currently. This is something Mobile Access Blade supports today.&lt;/P&gt;
&lt;H3&gt;Will this be integrated with CloudGuard Connect?&lt;/H3&gt;
&lt;P&gt;Initially, no, but this is planned for early next year.&lt;/P&gt;
&lt;H3&gt;What Identity Providers are supported?&lt;/H3&gt;
&lt;P&gt;Okta, Duo, Azure AD, onelogin, Ping.&lt;/P&gt;
&lt;H3&gt;Is Multiple Concurrent IDPs supported?&lt;/H3&gt;
&lt;P&gt;Not currently, but the "dual-mode" of several IDPs, plus IDP and Local Directory is on the short-term roadmap.&lt;/P&gt;
&lt;H3&gt;Is Local (On-prem) AD supported?&lt;/H3&gt;
&lt;P&gt;Yes, assuming the AD is accessible from the Docker agent installed on-premise.&lt;/P&gt;
&lt;H3&gt;Do I need to allow any inbound access on my perimeter gateways?&lt;/H3&gt;
&lt;P&gt;No, a Docker agent installed on-premise will initiate an outbound HTTPS connection to the Check Point cloud and will proxy all authorized traffic inbound to the datacenter.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;How are applications that require port ranges/dynamic ports supported?&lt;/H3&gt;
&lt;P&gt;We support applications that tunnel over web, RDP, SQL, or SSH (including SSH tunneling). We do not support arbitrary applications.&lt;/P&gt;
&lt;H3&gt;How much latency is added to application access?&lt;/H3&gt;
&lt;P&gt;It is similar to an nginx reverse proxy, which is minimal. Our data plane is located in many different regions to reduce latency.&lt;/P&gt;
&lt;H3&gt;Will the gateway decrypt the HTTPS connection from the browser and re-establish another HTTPS connection to the connector?&lt;/H3&gt;
&lt;P class="p1"&gt;Yes. Since the solution is DNS based we own our own certificate and will send it once opened to the server side (trusted proxy).&lt;/P&gt;
&lt;H3 class="p1"&gt;Where is the user activity video stored?&lt;/H3&gt;
&lt;P&gt;In AWS Encrypted File Store. Access to this is limited to admins and is stored by default for 30 days.&lt;/P&gt;
&lt;H3&gt;Are the user activity recordings indexed?&lt;/H3&gt;
&lt;P&gt;RDP is not indexed, SSH indexing is on the roadmap.&lt;/P&gt;
&lt;H3&gt;Can you explain the end-to-end connection flow?&lt;/H3&gt;
&lt;P&gt;The user authenticates to the controller (hosted in the cloud), which returns a list of available applications. Any authorized access to these applications is routed through the gateway to the on-premise Docker agent.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Is this a replacement for Mobile Access Blade?&lt;/H3&gt;
&lt;P&gt;It is a complimentary solution to Mobile Access Blade.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;What SaaS apps are supported?&lt;/H3&gt;
&lt;P&gt;Any web-based SaaS app is supported.&lt;/P&gt;
&lt;H3&gt;Will VDI be supported for both VMware and Citrix?&lt;/H3&gt;
&lt;P&gt;Depends on the use case. We generally recommend using RDP.&lt;/P&gt;
&lt;H3&gt;Is this integrated with SmartConsole and/or Infinity Portal?&lt;/H3&gt;
&lt;P&gt;No, this is not integrated with SmartConsole. We plan to have this as part of Infinity Portal by the end of 2020.&lt;/P&gt;
&lt;H3&gt;Can you access SmartConsole via Odo?&lt;/H3&gt;
&lt;P&gt;Only via a machine accessible with RDP. Once a web-based SmartConsole is available (planned in the R81 timeframe), this should be accessible via Odo.&lt;/P&gt;
&lt;H3&gt;Can RDP Copy/Paste be blocked when connected via Clientless mode?&lt;/H3&gt;
&lt;P&gt;Yes, we can also block download of files per configuration.&lt;/P&gt;
&lt;H3&gt;Is VNC supported?&lt;/H3&gt;
&lt;P&gt;Not currently. If this is of interest, please contact your local Check Point office.&lt;/P&gt;
&lt;H3&gt;Does this replace VPN?&lt;/H3&gt;
&lt;P class="p1"&gt;VPN replacement is a possible use case for Odo, although Odo does not fully replace VPN. Odo only supports Web, SSH, RDP and some database access. As such, it is not a full replacement for Mobile Access Blade, Remote Access VPN, or Site-to-Site VPN.&lt;/P&gt;
&lt;H3 class="p1"&gt;If applications are defined in an existing IdP, what is the process for moving them to Odo?&lt;/H3&gt;
&lt;P class="p1"&gt;The app URL will change as we provide a new FQDN for each app.&lt;/P&gt;
&lt;H3 class="p1"&gt;Will a DLP solution be integrated?&lt;/H3&gt;
&lt;P&gt;This is planned for next year as part of CloudGuard Connect.&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 16:55:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-s-New-SASE-Solution-Powered-by-Odo-Video-Slides-and/m-p/98456#M68</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-07T16:55:35Z</dc:date>
    </item>
  </channel>
</rss>

