Hello,
We faced the same issue. These connections overloaded our proxy. I understand it is a normal behavior, according to TAC, Under the hood Anti-Malware E2 is part of Threat Emulation blade and cannot function independently. Therefore Threat Emulation as blade is installed, no matter how it is called Threat Emulation or File reputation.
. We found some options:
- Reduce the number of connections that agents do to those URL's. It needs to disable some fetures which reduces security. (File reputation, custom IoC, create exclusions for browsers cache folders)
- Use semi isolated enviaroments Super Node, all file-rep connections will go to Super Node. It does not work with authenticated proxy.
- Send these connections to a different proxy configuring > > . Again, it does not work with authenticated proxy! It should be fixed on E88.70.
Just a tip. Make sure that all CheckPoint URL's are allowed on your proxy for endpoints. We found a couple endpoints without permissions to file-rep URL, and they went crazy, sent hundreds of attempts until we allowed the connection.
Regards