Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vladimir
Champion
Champion

Going all in?

I'd like to ask members' opinion about Check Point(ification) of the business.

While all of us have heard and seen the arguments in favor of consolidation of security product for the sake of compatibility and efficiency, I am presently contemplating a possibility to actually doing that.

While I am pretty familiar with the gateways and IaaS products and to some degree with the endpoint, I've never had an opportunity to see the all CP shop.

If any of you have worked in these environments, please share your opinions, impressions and gotchas?

Are there any components, (other than proxy), that should be integrated, if I am going for the best possible coverage of hybrid AD, O365 and other SaaS apps, with particular focus on Salesforce.

DLP will be predominant factor in my choice of the products, or their combination.

Good granularity and ease of setup and administration of DLP function is important.

 

Thank you,

Vladimir

 

1 Reply
Lari_Luoma
Ambassador Ambassador
Ambassador

Here are some comments and pointers that might be useful for you.

First of all make sure you have correct security in correct places. Don't enable all blades in all gateways, but make a design and analyze what kind of security is relevant and where.

CloudGuard SaaS

https://community.checkpoint.com/t5/CloudGuard-SaaS/One-administrative-CloudGuard-SaaS-documentation...

Access Control

- Utilize inline layers with security zones

- For identity awareness consider different identity sources such as identity collector that can be very useful in larger environments. It also integrates smoothly with Cisco ISE.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

- Understand the capabilities of Unified policies. You mentioned DLP, but also make sure you are familiar with Content Awareness that is natively part of R80.x installation without a special license.

Threat Prevention

https://community.checkpoint.com/t5/IPS-Anti-Virus-Anti-Bot-Anti/IPS-Ease-of-Use-in-R80-20-TechTalk/...

 

 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events