Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Alex-
Leader Leader
Leader

Air-gapped endpoints in environment using EpmaaS.

One of our customers is using Infinity Harmony Endpoint for regular endpoints like computers, servers.

They have a requirement to deploy a few computers which would be in a completely isolated network and location for accessing and managing privileged information.

The framework requires a standalone EDR solution.

I've read Deploying Harmony Endpoint in an Offline (Air-Gapped) Environment which describes a completely offline installation of EPS server along with TE appliance.

As the customer is already using the online Endpoint, the question is whether we can leverage the existing option of creating a full standalone package, including signatures, installing locally and leave it offline, knowing the limitations of blades when offline, and update the signatures manually without access to any management server.

0 Kudos
7 Replies
G_W_Albrecht
Legend Legend
Legend

Updating Signatures offline needs an On-Premise EPSS  Management Server as documented in sk182535. So you can ask CP TAC if Infinity EPS could be used, but but signature update, using a TE appliance and its update will not be possible.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
lluner
Advisor

@Alex- 

You could use the supernode, the link is below. In addition, you could implement the endpoint firewall, only allowing access to the supernode.

Super-Node

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Also the supernode needs internet access, so it can not be used in a completely isolated network !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
lluner
Advisor

tks

0 Kudos
Alex-
Leader Leader
Leader

@lluner @G_W_Albrecht Thanks for chiming in.

This project has stringent requirements, so partial or derived Internet access like the super node is not compliant.

We will then explore if the air-gapped architecture with HEP can be considered.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Please, do not adress me in a language i do not understand.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Don_Paterson
Advisor
Advisor

You could ask you SE if Check Point will support a data diode. For example Owl. 

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events