- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Does anybody have any experience with running Endpoint Security in a VMware Horizon View infrastructure with instant clones? I have found two related threads on CheckMates here (here and here) but they are not really conclusive to me.
If working with Instant Clones, the EP client would be deployed on the master image. Whenever a new VDI session is being established to Horizon View, a new clone of this image would be deployed. However, since the EPGUID of the master is already registered with the EPS server, the clone would not be able to synchronize with the EPS server (duplicate EPGUID on the server). Are my assumptions correct? Is there any design guide or paper whatsoever on this subject? I can't find anything neither in SK nor in the admin guides. I also cannot find an explicit statement as to the support of Endpoint Security with VMware Horizon View.
In general we have plans to support VDI environments later this year. Recommend connecting with your local office on this.
You are correct in that once an EPGUID registers, you can’t “clone” it and expect it work, at least not without performing extra steps.
In general we have plans to support VDI environments later this year. Recommend connecting with your local office on this.
You are correct in that once an EPGUID registers, you can’t “clone” it and expect it work, at least not without performing extra steps.
I have spoken to several Check Point representatives now (TAC, local office) and here is what I have so far:
We see an increasing number of customers interested in or switching to VDIs and they like the non-persistent mode (aka instant clones) as it simplifies patching significantly and saves disk space.
I am not well versed in VMware Horizon, but have you seen the release notes for E81.00?
They mention "Virtual desktop infrastructure (VDI) Persistent Support for VMWare Horizon" I don't know if this helps with what you were hoping to accomplish or not?
Not really - persistent mode was actually already working (although not officially supported) but persistent mode is basically just a virtualized workstation. It has its own persistent virtual disk and is a full Windows installation, so if you have 500 clients you need to patch and update 500 individual clients. With non-persistent mode, there is - basically - one master image which is being cloned the moment a user logs in and is being destroyed when the user logs out. So disk space is only used when the virtual machine is actually in use. And if you need to patch and update software, you only need to do this on the master image. It's a really nice technology but of course software like Check Point Endpoint Security (and other Endpoint Security products) are not working because they rely on their own unique identifiers for workstations but the non-persistent VDI clients are all clones of one master image.
Any update on this topic? Does 81.30 support instant clones?
I don't think so, the release notes for E81.30 don't state anything related to VDI deployments and since the feature would constitute a significant change in the way endpoint clients communicate with policy servers, I assume it would be something that you would find in the release notes.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY