- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Checkmates --
What are checkpoint options for deployment of dedicated "update server" to be placed on DMZ allowing Security Gateways to receive updates for advanced blade features.
This not a new topic for certain Govt networks and Utility SCADA networks where Internet isolation is best practice.
The keys:
1) advanced features enabled on Checkpoint gateways: IPS, Antibot, AppCtl.
2) checkpoint gateway can't talk outside local network (ie. can't communicate directly with Checkpoint public update servers).
3) granular communication to specific "update server" on DMZ is permissible.
Advise on thoughts. thx
The term you should ask about is "Private Threat Cloud" or PTC. My environment has some. I strongly recommend against them. They've given us nothing but headaches.
Hello @Bob_Zimmerman -- thanks for the quick reply and insight.
Yes -- I suggest the customer will be excited about solution:
1) not a headache
2) no additional cost
Speaking of headaches and PTCs, the firewalls which use the PTCs have been failing to get updates for a few days. The PTC health report said everything is fine. Turns out the certificates the PTCs present for the name updates.checkpoint.com just expired with no warning, and that isn't checked in the health report.
It's a minor issue, but frustrating. Cost some coworkers a few hours trying to figure out what was going on.
PTC or a Proxy are the solutions that come to mind.
IPS and App Control have actual signatures that can be downloaded.
Most everything else is a dynamic lookup to ThreatCloud, for which you would need Private ThreatCloud: https://support.checkpoint.com/results/sk/sk149692
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY