Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
r31N3r
Participant
Jump to solution

What frequency to CWS

Hello,

Can me anyone tell what is the correct frequency  a cluster-(ip) should connect to  http://cws.checkpoint.com/Malware/malware/6.0?  or  http://cws.checkpoint.com/AntiVirus/antivirus/2.0? ?  In our environment , AV and Antibot enabled, it seems to be a streaming connection. Is this O.K.?

Thank you for your replies in advance

Reiner

0 Kudos
2 Solutions

Accepted Solutions
_Val_
Admin
Admin

This is normal, AV/AB/IPS are in constant communication with the ThreatCloud. 

View solution in original post

(1)
PhoneBoy
Admin
Admin

If AV/AB are enabled, calls to those URLs and others listed in sk83520 are to be expected relative to the traffic the gateway is seeing.
It's expected behavior.

View solution in original post

(1)
7 Replies
the_rock
Legend
Legend

Might be worth TAC case to confirm this...excellent question by the way @r31N3r 

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Confirm what ? He did not present any answer that can be confirmed, but only a question still not answered by anyone 😉

I would  go for 12h.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

Confirm answer to his question 😇

0 Kudos
G_W_Albrecht
Legend Legend
Legend

What do you mean by frequency ? How often per week / day you connect and update  ? This can be selected according to your prefered interval. sk83520 - How to verify that Security Gateway and/or Security Management Server can access Check Poi...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
r31N3r
Participant

We set in the SmartDashboard "Traditional Anti-Virus"  120min and "Proxy1".

On "Proxy 2", set in Global Properties or in Custer Object, the log for cws.checkpoint.com is running like there's no tomorrow.  All states IPS/AV Signature on for the cluster are "green".

 

_Val_
Admin
Admin

This is normal, AV/AB/IPS are in constant communication with the ThreatCloud. 

(1)
PhoneBoy
Admin
Admin

If AV/AB are enabled, calls to those URLs and others listed in sk83520 are to be expected relative to the traffic the gateway is seeing.
It's expected behavior.

(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events