Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Matlu
MVP Silver
MVP Silver
Jump to solution

Restricting Files via Check Point

Hello, everyone,
I want to prevent a user or group of users from “uploading” documents to the corporate SharePoint site.
This traffic flows through our firewall cluster.
Can this be achieved in Check Point using a specific blade?
Should we consider hardware resource capacity (memory/disk) before enabling any blade to perform this task?
Thank you for your comments.

0 Kudos
1 Solution

Accepted Solutions
CaseyB
Advisor

Sounds like this could work with the combination of the Content Awareness Blade + HTTPS Inspection.

Content Awareness Software Blade

View solution in original post

0 Kudos
7 Replies
CaseyB
Advisor

Sounds like this could work with the combination of the Content Awareness Blade + HTTPS Inspection.

Content Awareness Software Blade

0 Kudos
Matlu
MVP Silver
MVP Silver

Do I need to enable HTTPS Inspection to achieve this?
Would I also need to use the APPC blade?
Something like this: APPC + Content Awareness + HTTPS Inspection?
Could this “put a heavy load” on the device's memory and CPU?

0 Kudos
CaseyB
Advisor

If your on-premise Sharepoint is using HTTPS, then I would say it is likely HTTPS Inspection would be needed for it to work properly as it would need to be able to see content, but testing could reveal otherwise.

A rule like this might work:

sp-drop1.png

OR

sp-drop2.png

I cannot speak to the additional resources required for this; we do not run Content Awareness.

 

0 Kudos
PhoneBoy
Admin
Admin

App Control and Content Awareness use the same underlying infrastructure and does have a performance impact over running Firewall only (no other blades).
HTTPS Inspection will definitely increase the load on your gateways independent of the above.

0 Kudos
Matlu
MVP Silver
MVP Silver

To get the most out of both the APPC and Content Awareness blades, is it always recommended to enable HTTPS Inspection?

0 Kudos
josi
Participant
Participant

You can detect and block entire apps with APPC, but to detect and block only uploads/downloads you have to enable HTTPS Inspection.

It is specifically stated in sk112249 - Best Practices - Application Control

0 Kudos
PhoneBoy
Admin
Admin

Content Awareness requires HTTPS Inspection since almost no web traffic isn't HTTPS anymore.
App Control can function without HTTPS Inspection, though some applications cannot be correctly identified without HTTPS Inspection.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events