- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello -- Checkpoint has released E83 Endpoint Security (home link).
Amongst the fixes and new features, there is now URLF at the endpoint leveraging browser plugin. Note the plugin will see inside HTTPS sessions so this effectively negates the need for gateway HTTPS decrypt for large portion of scenarios. I understand release 1.0 is for Chrome/Windows but wider browser and platform support coming.
The question:
The URLF filter is a browser plugin. Also, the SBA (Sandblast Agent) includes Browser extension for (a) phishing protection, and (b) credential theft.
Will these two plugins be merged to avoid endpoint administrators managing multiple checkpoint browser extensions?
there are no 2 extensions. both are part of the same extension which is part of Sandblast Agent deployment.
thanks @Lior_Arzi and @PhoneBoy
Since current E83 release only Windows endpoint today, is the SBA browser plugin still only Chrome on Windows?
What about MACOS (for URLF via browser plugin)?
What about Firefox?
thanks -Garrett
Note: I was reminded today on session that Checkpoint Capsule Connect does support URLF for both Windows and MACOS but doesn't support Catalina. With the current Capsule Connect solution being deprecated and replacing by future Cloudguard Connect for Users solution (with future consolidated agent that has yet been developed), we are asking Capsule customers to take a completely different architecture for future. If customers like the network shim/service, expecting these same customers to be OK with change to browser plugin for URLF is significant leap of faith.
Hello @Lior_Arzi . sincere thanks for the update and details.
Our local CP team has idea that the product Capsule Connect, with it's URLF functionality, will be replaced by a future "unified agent" that has yet to be developed. They perceive the replacement for Capsule Connect will not be Endpoint Security SBA, etc.
The current limitation of Capsule Connect is it will not be updated to support MACOS catalina and the related security coding changes.
Can you provide any insight? thanks in adv. -GA
If you use SBA (including the browser extension) you are well covered.
it depends on what you want to get:
If you want a Secure Web Gateway replacement, to protect the web vector, both solution will give you more or less similar coverage assuming you enable SSL inspection on Capsule Connect (there are some other differences but they are minor).
But on SBA you also get much more comprehensive endpoint protection solution. not just for the web vector.
when using Capsule connect you will still need to add an endpoint solution. Either SBA or some other endpoint solution.
hope this was helpful.
feel free to contact us if you have additional questions. either here, or at arzil@checkpoint.com
Hello @Lior_Arzi - thanks for reply and details.
I can reference various customers on this dialog. All existing Checkpoint customers and have long discussed the idea of HTTPS decrypt at gateway and have resisted for various reasons.
With current coronavirus remote working conditions, various customers asking for solutions to add URLF visibility to end-users as additional forensics layers to augment their existing end-point protection.
In most cases, Checkpoint network/gateway customers do not have Endpoint Security. There are various reasons behind this (CP lack of marketing and product visibility in sector, lack of participation in industry groups like MITRE Attack Framework bake-off testing for endpoints, customer desire to not have "all eggs in one basket", and finally -- ongoing tech bug/stability issues on gateways makes customer hesitant to invite similar experience on endpoints).
It's very important for Checkpoint endpoint product team to understand that having an endpoint solution that is packaged and marketed to "augment" existing endpoint security solution is VERY IMPORTANT for north american sales.
Checkpoint has brought some very powerful and useful endpoint tools to endpoint platform. specifically, the browser plugins to help insure end-user doesn't make bad decisions. ie. phishing protection and credential theft and re-use. I recall this was originally called "SBA for Browsers" and sold as such.
The current most "minimal" offering is now Endpoint Security SBA BASIC. This includes all the endpoint security tools that competes directly other malware security vendors. This is a political issue we must avoid and it can be solved by packaging and pricing. Note: the message to customer must not be "you can simply not use the advanced features" - it must work like "augment" existing endpoint product "out of box" and will not introduce conflicts, hassle, instability.
WE need ability to (a) add more features and value on browser plugin side with wider platform support, more features including URLF, (b) ability to turn OFF all the endpoint features to insure we're not "competing", and (c) update pricing to reflect a SBA Browsers option. This allows CP to "get in the door" and wait for competing vendor to mis-step allowing CP to swoop in and save day by simply "turning on features".
Thus, I would like the following product -- priced CHEAPER vs SBA Basic:
I have repeatedly fielded comments from customers asking for additional visibility and logging on endpoints to better understand -- and validate/confirm -- other logging sources. The idea of URLF logging is NOT a productivity issue but rather additional context for forensics investigation (ie. what were the sites visited by end-user before an "event" that needs to be investigated).
thanks and 0.02.
-GA
@Garrett_DirSec- in response to your suggestion dated 2020 to release a "slim and lightweight" Check Point Agent allowing to filter and monitor the endpoint. Do you think Sandblast nano Agent aka Harmony Browse (SandBlast Agent for Browsers SBA4B) delivers the functionality you were aking for? Thanks!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY