- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
I have a customer who's sole reason to stick with the MDS is the ability to have common IPS policy across multiple gateways that have individual Access Control, URLF and App Control policies.
Is there a way to have common IPS or threat prevention policy (with obvious caveats that MTAs will be excluded) in SMS?
Since we have the ability to create custom profiles containing rules that could be selectively installed on particular gateways or clusters, this feature seem to be a very logical one to have.
Thank you,
Vladimir
MDS allows applying the same global IPS policy to multiple GWs belonging to different security domains. There is no problem assigning the same Threat Prevention profile to multiple GWs under the same management.
Valeri,
Let me clarify what I am trying to achieve:
Using SMS with different policy packages, where each policy package is applied to a number of gateways or clusters, I would like to use common IPS or TP policy across all of them.
Yes, we can use common profile for multiple policy packages, but this will necessitate multiple installations of the TP policies, one for each policy package.
The idea is to have same capability in regards to TP/IPS in SMS as presently exists in MDS only: single policy that could be installed to multiple targets irrespective to their policy package membership.
Regards,
Vladimir
Hi Vladimir, this is available starting with R80.20.M1 - you can share a Threat Prevention Layer across multiple policies, both in Multi-Domain and Security Management Servers. Raz Shlomo
(colors are different because it's taken off the more advanced R80.20 EA, but you can do that with R80.20.M1)
Thank you Tomer!
This is exactly what I had in mind.
Okay, it is clear now. I see Tomer is already providing you with the info you need. Please do join our webinar tomorrow, you will hear about this and other interesting features coming up with the new management release update.
Thank you Valeri, I'll be on it tomorrow.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY