cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question
Vladimir
Pearl

Create and maintain Shared IPS Layer with R80.X gateways ?

I have a customer who's sole reason to stick with the MDS is the ability to have common IPS policy across multiple gateways that have individual Access Control, URLF and App Control policies.

Is there a way to have common IPS or threat prevention policy (with obvious caveats that MTAs will be excluded) in SMS?

Since we have the ability to create custom profiles containing rules that could be selectively installed on particular gateways or clusters, this feature seem to be a very logical one to have.

Thank you,

Vladimir

Tags (2)
6 Replies

Re: Create and maintain Shared IPS Layer with R80.X gateways ?

MDS allows applying the same global IPS policy to multiple GWs belonging to different security domains. There is no problem assigning the same Threat Prevention profile to multiple GWs under the same management. 

0 Kudos
Vladimir
Pearl

Re: Create and maintain Shared IPS Layer with R80.X gateways ?

Valeri,

Let me clarify what I am trying to achieve:

Using SMS with different policy packages, where each policy package is applied to a number of gateways or clusters, I would like to use common IPS or TP policy across all of them.

Yes, we can use common profile for multiple policy packages, but this will necessitate multiple installations of the TP policies, one for each policy package. 

The idea is to have same capability in regards to TP/IPS in SMS as presently exists in MDS only: single policy that could be installed to multiple targets irrespective to their policy package membership.

Regards,

Vladimir

Re: Create and maintain Shared IPS Layer with R80.X gateways ?

Hi Vladimir, this is available starting with R80.20.M1 - you can share a Threat Prevention Layer across multiple policies, both in Multi-Domain and Security Management Servers. Raz Shlomo

(colors are different because it's taken off the more advanced R80.20 EA, but you can do that with R80.20.M1)

Highlighted
Vladimir
Pearl

Re: Create and maintain Shared IPS Layer with R80.X gateways ?

Thank you Tomer!

This is exactly what I had in mind.

0 Kudos

Re: Create and maintain Shared IPS Layer with R80.X gateways ?

Okay, it is clear now. I see Tomer is already providing you with the info you need. Please do join our webinar tomorrow, you will hear about this and other interesting features coming up with the new management release update.

0 Kudos
Vladimir
Pearl

Re: Create and maintain  Shared IPS Layer with R80.X gateways ?

Thank you Valeri, I'll be on it tomorrow.

0 Kudos