Hello Checkmates --
What are checkpoint options for deployment of dedicated "update server" to be placed on DMZ allowing Security Gateways to receive updates for advanced blade features.
This not a new topic for certain Govt networks and Utility SCADA networks where Internet isolation is best practice.
The keys:
1) advanced features enabled on Checkpoint gateways: IPS, Antibot, AppCtl.
2) checkpoint gateway can't talk outside local network (ie. can't communicate directly with Checkpoint public update servers).
3) granular communication to specific "update server" on DMZ is permissible.
Advise on thoughts. thx