Hi,
We have multiple Check Point security gateways for different purposes in our infrastructure.
The firewalls that we currently use for outbound Internet access have limited performance and we want to optimize the features that we have enabled on them. Currently we have the following features enabled for different use cases:
- URL filtering
- Application control
- Custom Applications/Sites
- Domain objects
- Updateable objects
- Anti-Bot
We are considering HTTPS inspection, but for now we are only using Categorize HTTPS sites. At the moment we are not planning to use Threat Extraction, Content Awareness, Identity Awareness, Anti-virus/Anti-spam or Data Loss Prevention.
Are there any other features (e.g. IPS features to prevent DNS and ICMP tunneling) that you would recommend that we implement? We would prefer to not enable the full IPS features since this could have a high CPU impact and many signatures would not be relevant for outbound Internet access.
I am aware that a best practices document has been shared in the following thread, but it does not contain many technical details.
https://community.checkpoint.com/t5/General-Topics/White-Paper-Internet-Web-Access-Security-Best-Pra...
We are currently using R80.20 take 183, but are planning to upgrade to R80.40.
Thanks for your help!
Best regards,
Harry