- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Dear all,
I would like to activate ICAP server on a Sanblast appliance in r80.10 managed by a management also in r80.10.
The only documentation that I find is to activate on the r77.30 or on a r80.10 but managed by a R80.20.
Is it possible to do anything, or do we have to upgrade the management in R80.20 ?
Best regards,
Thomas Kündig
Hi Thomas,
ICAP server is only available on R77.30 JHF releases and is not included or planned to for R80.10 or it's JHFs. ICAP server is planned to be included in the R80.20 GW release with several improvements. The EA team is looking for R80.20 EA customers so that might be an option. https://community.checkpoint.com/thread/7612-check-point-r8020-production-and-public-ea
It is also important to notice that R80.10 on a SandBlast appliance is currently in EA and not officially supported (sk106210). The plan is to have it supported with the next JHF GA that will include several fixes.These fixes are already part of R80.20. But, there will be no ICAP server on R80.10.
So, if ICAP server is needed I would recommend returning to R77.30 on the SandBlast appliance for now or take part in the E80.20 EA.
HTH,
Christian
Both sk111305 and sk111306 only speak of R77.30 - the same is true of sk122486 for R80.20 M1. Where did you find the information on how to enable ICAP in R80.10 managed by R80.20 M1?
Dear Günther,
After a second read of this :
ICAP Server support for Threat Prevention
I saw that it should be enable soon.
So, I think that I answared to my question myself. But it means that we lost this features after an upgrad ?.. Or does it have a solution ?
Best regards,
Thomas Kündig
sk123412 only speaks of R80.10 GWs with unavailable Jumbo installed; the Jumbo will be published soon. So it is not possible to use R80.10 GW for ICAP at the present time, the only possibility is R77.30 managed by SMS R77.30 or R80.20 M1.
So as long as there is no SMS Jumbo for R80.10 even with the R80.10 GW Jumbo you will need SMS R80.20 M1.
Hi Thomas,
you can found a integration overview in following articles:
Symantec (Bluecoat) SG ICAP and Sandblast (TEX)
Fortigate Firewall ICAP and Sandblast (TEX) (better use a Check Point firewall:-)
McAfee Web Gateway ICAP and Sandblast Appliance (TEX)
Or ask Thomas Werner, he is a very good Check Point TE expert.
Regards,
Hi Thomas,
ICAP server is only available on R77.30 JHF releases and is not included or planned to for R80.10 or it's JHFs. ICAP server is planned to be included in the R80.20 GW release with several improvements. The EA team is looking for R80.20 EA customers so that might be an option. https://community.checkpoint.com/thread/7612-check-point-r8020-production-and-public-ea
It is also important to notice that R80.10 on a SandBlast appliance is currently in EA and not officially supported (sk106210). The plan is to have it supported with the next JHF GA that will include several fixes.These fixes are already part of R80.20. But, there will be no ICAP server on R80.10.
So, if ICAP server is needed I would recommend returning to R77.30 on the SandBlast appliance for now or take part in the E80.20 EA.
HTH,
Christian
Dear Christian,
Thank you, that was I understood ! Thank you for your confirmation !
Best regards,
Thomas Kündig
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY