- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: How can I install multiple policies at the sam...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How can I install multiple policies at the same time?
Tomer, can you clarify if this common IPS/TP layer could be installed on all targets in all policies simultaneously, or is the installation still limited to a single group of gateways/clusters managed by the parent Access Control policy?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You still have to select the policy + the gateways at the policy installation dialog. If the policy is not the same across your gateway group, then this means picking a different policy package at every time. The term is a Policy Package which includes Access Control + Threat Prevention.
BUT we're simplifying that soon as well https://community.checkpoint.com/events/1080-techtalk-r8020-demo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Any clue as to ETA?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Of the TechTalk? Sure - this Wednesday J
I want to present the feature and then if you think that this can help simplifying this scenario then we can talk about ETAs / how to enable it from the public EA.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So the feature that I wanted to mention was the ability to Schedule Policy Installations with R80.20 (not M1). It is in the current public EA as well as the upcoming next Management Feature Release.
You can create a preset with multiple policies or multiple gateways in it. Then, you can either play it with one click or add a time object to schedule it to a time window.
This way you could install multiple different policies at once.
You can use this feature if you are a Multi-Domain user by logging into the MDS domain and going to Install Policy Presets.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tomer,
I've seen it during the demo being used with Access Control policies. Can you confirm that this is applicable to TP policies decoupled from access control as well?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, for this version it will always install both policies.
So it looks that a solution to your use case remains with writing custom API scripts that batch-calls "install-policy access false threat-prevention true" on each of the targets.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the info Tomer.
Unfortunately, client is not interested in using scripts.
Looks like we are stuck with MDS for the duration.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does only the management need to be 80.20 to schedule installs? Will it still be able to push scheduled installs down to 80.10 or even 77.30 gateways (as long as the policy is appropriate for that version)?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, you can push scheduled installs even for R77.30 (tested).
The only issue I found is that it is not working in case you need to push firewalls based on their policy package:
https://community.checkpoint.com/thread/9712-install-policy-presets-not-working-on-r8020
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gateway version doesn't matter.
Management version should be R80.20 and above and has to be a Multi-Domain environment in order to schedule policy installations from the GUI.
With the Management API of R80 and above, you could create a schedule policy installer with a Cron job.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tomer,
Any way the features that could benefit single domain users, (such as the one discussed above) could be made available in the SMS and not be exclusive to MDS?
