Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
s_milidrag
Contributor
Contributor
Jump to solution

Managing endpoint clients when they are outside of the LAN

Hi 

For the purpose of managing endpoint clients when they are outside the Local network with an on-prem management server, I have had to expose the management server to the Internet (static NAT) and create a firewall rule to allow only HTTPS communication.

Is this safe, since I see a lot of connections & attack attempts on my EP SMS?

Endpoint SMS is behind the Check Point firewall, and I am also using the same SMS to manage firewalls.

 

Thanks 

 

 

 

SM
0 Kudos
1 Solution

Accepted Solutions
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Likely you qualify for an "Endpoint Policy server" license that you can put in the DMZ as an alternative if you would prefer.

CCSM R77/R80/ELITE

View solution in original post

(1)
3 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Likely you qualify for an "Endpoint Policy server" license that you can put in the DMZ as an alternative if you would prefer.

CCSM R77/R80/ELITE
(1)
s_milidrag
Contributor
Contributor

Thanks,

I think this is the only reasonable setup

SM
0 Kudos
the_rock
MVP Diamond
MVP Diamond

What Chris said definitely makes sense.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 07 May 2026 @ 01:30 PM (AEST)

    CheckMates Live Sydney

    Tue 02 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Aarhus

    Wed 03 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Copenhagen
    CheckMates Events