- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Schedueled policy installs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Schedueled policy installs
Hi,
I am looking to find where schedueled policy installs are initiated from.
The reason for this is that every night i see automated threat prevention policy installs but i cannot find where they are configured.
Environment is R81.10 Take79 and it is an SMS.
There are no smart tasks configured, at least not what i can see, are they unique and only visible for each user ?
No other schedueled tasks are configured.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Look for IPS Updates settings ! Scheduled Updates can end with a policy install: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@G_W_Albrecht is correct. Go to - SmartConsole > Security Policies > Threat Prevention > Custom Policy
At the bottom go to - Custom Policy Tools > Updates > Schedule Update.
The second option allows you to configure when policy is installed following a successful update.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Look for IPS Updates settings ! Scheduled Updates can end with a policy install: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@G_W_Albrecht is correct. Go to - SmartConsole > Security Policies > Threat Prevention > Custom Policy
At the bottom go to - Custom Policy Tools > Updates > Schedule Update.
The second option allows you to configure when policy is installed following a successful update.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Should not be necessary if gateway is configured to update IPS itself right ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Still needs to enabled manually.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is found here: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/...
Check Point wants the customer to be protected. When a protection update is available, Check Point wants the configuration to be automatically enforced on the gateway. You can configure automatic gateway updates for Anti-Virus, Anti-Bot, Threat Emulation and IPS.
For Anti-Virus, Anti-Bot and Threat Emulation, the gateways download the updates directly from the Check Point cloud.
For IPS, prior to R80.20, the updates were downloaded to the Security Management Server, and only after you installed policy, the gateways could enforce the updates. Starting from R80.20, the gateways can directly download the updates. For R80.20 gateways and higher with no internet connectivity, you must still install policy to enforce the updates.
When you configure automatic IPS updates on the gateway, the action for the newly downloaded protections is by default according to the profile settings.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure if that is correct any longer:
"For IPS, prior to R80.20, the updates were downloaded to the Management server, and only after you installed policy, the gateways could enforce the updates. Starting from R80.20, the gateways can directly download the updates. For R80.20 gateways and higher with no internet connectivity, you must still install policy to enforce the updates"
Please correct me if am wrong but if gateway HAS internet access then this scheduled install is not needed according to above text from documentation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If the GW is configured to install Updates and has internet access, scheduled policy install is not necessary. You will only need a policy install when changing IPS protection settings.
