Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Tal_Ben_Bassat
Employee
Employee

Looking for your feedback to expand the Quantum automations in Infinity Playblocks 🌟

Hi everyone,

Infinity Playblocks is a powerful automation platform that enhances security operations by connecting various Check Point solutions, including Quantum, Harmony, and third-party security tools. Playblocks reads logs, triggers automated responses, and performs actions like isolating hosts, blocking IPs, and notifying administrators when threats are detected. 

We’re looking for your feedback and ideas for automation use cases that can enhance your daily security processes.

  • Are there specific alerts or notifications you would like to receive from Playblocks?
  • Is there any action you would like to automate that could strengthen security in your environment?

We would love to hear your input! 🚀

Please share your thoughts in the comments or reach out to me directly at talbb@checkpoint.com .

Additionally, if you're interested in a one-on-one session to explore how Playblocks can further enhance your Quantum Management, just let me know!

Looking forward to hearing from you,

Thanks,

Tal

8 Replies
the_rock
Legend
Legend

Hey @Tal_Ben_Bassat 

I recall when my colleague and I tested it while back, there was an issue where we could not exmpt whole subnet, but rather just a single IP address. Not sure if thats still the case or not.

Andy

0 Kudos
Tal_Ben_Bassat
Employee
Employee

Hi Andy @the_rock , 

Playblocks supports today blocking entire subnets or ranges, in addition to individual IP addresses.

You can find this on the Lists page in Playblocks application. 

If you have any other questions or need further assistance, please feel free to reach out.

Also, if you have any ideas to share, I’d love to hear them!

Thanks

Tal 

 

the_rock
Legend
Legend

Good to know! I remember one idea my colleague and I asked about was if its possible to block things based on time range. So say block something 9am to 9 pm, but allow it 9pm to 9am.

Possible?

Andy

0 Kudos
Tal_Ben_Bassat
Employee
Employee

Hi Andy @the_rock ,

That's an interesting idea! Currently, Playblocks allows you to block IPs for a specified duration with an expiration time, but blocking based on a specific time range isn't supported at this moment.

Could you share more about the use case for blocking malicious IPs during specific hours? Understanding the rationale behind this could help us promote the feature.

Thanks for your input!

Tal 

the_rock
Legend
Legend

Good afternoon Tal,

Yes, glad you asked me that question. Funny story, but it was not the actual client my colleague and I were doing this for in initial stages (it was just testing, they could not roll it in production, due to some other way more important projects at the time), but I mentioned it to another client when we went for drinks and he said to me "Andy, since we have contractors doing work in other countries, can that work based on time based blocking?"

Thats why I was wondering, because that client would say ONLY want certain people to have access during the day time, but not overnight.

Hope that helps.

Andy

0 Kudos
Tomer_Noy
Employee
Employee

Hi Andy,

Since this use-case sounds like a permanent policy in which you want to allow access to certain people, only at certain hours, it's a better fit for an access rule with a Time object. 

Playblocks is more about reacting to events and applying remediation. I wouldn't use it to periodically allow and block users according to schedule.

the_rock
Legend
Legend

Makes sense @Tomer_Noy 

0 Kudos
Tal_Ben_Bassat
Employee
Employee

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events