Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Garrett_DirSec
Advisor

Checkpoint option for DMZ-based update server

Hello Checkmates --

What are checkpoint options for deployment of dedicated "update server" to be placed on DMZ allowing Security Gateways to receive updates for advanced blade features.

This not a new topic for certain Govt networks and Utility SCADA networks where Internet isolation is best practice. 

The keys:

1) advanced features enabled on Checkpoint gateways:   IPS, Antibot, AppCtl.

2) checkpoint gateway can't talk outside local network (ie.   can't communicate directly with Checkpoint public update servers).

3) granular communication to specific "update server" on DMZ is permissible.    

Advise on thoughts.    thx

 

0 Kudos
4 Replies
Bob_Zimmerman
Authority
Authority

The term you should ask about is "Private Threat Cloud" or PTC. My environment has some. I strongly recommend against them. They've given us nothing but headaches.

0 Kudos
Garrett_DirSec
Advisor

Hello @Bob_Zimmerman -- thanks for the quick reply and insight.

Yes -- I suggest the customer will be excited about solution:

1) not a headache

2) no additional cost

 

 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

PTC or a Proxy are the solutions that come to mind.

CCSM R77/R80/ELITE
0 Kudos
PhoneBoy
Admin
Admin

IPS and App Control have actual signatures that can be downloaded.
Most everything else is a dynamic lookup to ThreatCloud, for which you would need Private ThreatCloud: https://support.checkpoint.com/results/sk/sk149692 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events