- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Anyone have experience with the 'zScaler Servi...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anyone have experience with the 'zScaler Services' Updatable Object - R81
We're running R81, and I'm looking to start using the 'Updatable Objects' - particularly the one marked 'Zscaler Services'.
Looking for the below:
- I assume these 'updatable objects' perform similarly to what's called 'ISDB Objects' in FortiGates.
- Do these perform well on CheckPoints?
- Does anyone know if this 'Zscaler Services' object includes both ZIA and ZPA?
- There are no published lists I can see to confirm this, just a link to the public Service Info page.
- How often are these updated by CheckPoint, or do they generally point to a public JSON/XML to update?
Thanks in Advance!
Dan
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
They are not polled from the management server, they are pulled directly from the gateways once an hour, I believe.
For how Domain Objects work, see: https://support.checkpoint.com/results/sk/sk90401
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We list sources for some applications here: https://support.checkpoint.com/results/sk/sk131852
zScaler is specifically listed, and I assume we are pulling the full JSON file they provide: https://config.zscaler.com/api/zscaler.net/cenr/json
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
All of our Updatable Objects are updated based on vendor-provided JSON/XML.
You should be able to see what's in them: https://community.checkpoint.com/t5/Security-Gateways/AWS-Updateable-Objects/m-p/99010
Or with: https://support.checkpoint.com/results/sk/sk161632
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks @PhoneBoy!
Couple follow up questions:
How often are the Vendor JSONs polled/updated by the management server?
Also a quick question while I have you (as I figure it's semi-related):
When using the Domain object (eg. www.checkpoint.com) in a destination, are those resolved IP's cached for some time before being re-polled, or does a resolution happen each time the policy is passed? I'm finding conflicting answers to this.
Thanks again!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
They are not polled from the management server, they are pulled directly from the gateways once an hour, I believe.
For how Domain Objects work, see: https://support.checkpoint.com/results/sk/sk90401
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Interesting - so each gateway which needs to reference a Updatable Object needs to DNS/Internet or Proxy capability?
I'm quite surprised it's not done from the management server.
Thanks for the SK, will read up on that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a way to see the URL where the vendor provided json is downloaded from? Then the question of thread opener could be answered.
@dnitskyI guess, ZIA and ZPA are both included as ZEN are used for both. I assume that all necessary targets should be achievable when used in a policy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We list sources for some applications here: https://support.checkpoint.com/results/sk/sk131852
zScaler is specifically listed, and I assume we are pulling the full JSON file they provide: https://config.zscaler.com/api/zscaler.net/cenr/json
