- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Re: SBA without management server
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SBA without management server
Can I use the SBA without management server ?
How its configuration ?
- Tags:
- sba
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
All Endpoint blades (including SBA) require a management server for deployment and collecting logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which blades will work on SBA if management is not available some time?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Management is definitely required for initial deployment.
Beyond that the blades can operate more or less independent of the management.
Forensics requires access to the management to generate reports.
Many of the blades require Internet access to leverage ThreatCloud.
Antiransomware will work without Internet at all.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
All blades will keep working even when disconnected from the management server:
- Anti Ransomware – will work. No connection needed.
- Forensics – full attack analysis will work. Remediation of the full attack based on this analysis will work. You can view the analysis locally from the EP/SBA client UI.
- Threat Emulation, threat Extraction – will work as long as you have connection to threat cloud or local TE appliance
- Anti Phishing & Anti Bot. – will work as long as you have connection to the threat cloud
What the management server is really needed for is policy management, licensing, central monitoring and update distribution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Lior,
If we use SandBlast appliance, do we need access from the client machines to the Internet, did they just have access to the appliance? How in the given case will the anti-bot work?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The clients need to access the TE appliance or ThreatCloud.
Anti-Bot needs Internet access to look up threat indicators.
We do offer a 'Private ThreatCloud' appliance, which I know our security gateways can use in the "no Internet" use case, but not sure on Endpoint... hopefully https://community.checkpoint.com/people/arzile9338099-64b6-3d9b-be29-fc67dc1788f6 can clarify.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As Dameon mentioned, for TE SBA can work either with the cloud or with a TE appliance, you can configure this in the management.
You do need the cloud for AB (we haven't certified yet 'Private Threat Cloud' appliance with SBA).
