- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Content available to CheckMates members:
We will add a video demonstrating the new Web-based SmartConsole shortly.
Selected Q&A is below.
We use a different upgrade infrastructure since R80.20 and use a different command to perform the migration: migrate_server
It works similarly to "migrate export" and is used when doing advanced upgrades.
R80.20 and above can upgrade directly to R81.
For earlier releases, it is a two-step process (upgrade to R80.40, then upgrade to R81).
This is listed in the R81 Installation and Upgrade Guide .
In general, any non-SMB appliance from the 2016 line on up. The complete list of supported appliances is in the R81 Release Notes. Older appliances will be blocked from installing R81.
While there is no specific timeframe for completely eliminating SmartDashboard, we remove more and more items from it in subsequent releases.
No, gateways can either use the class Threat Prevention profiles or the Infinity Threat Prevention profile.
They cannot use both profiles.
Yes.
You already have this with policy layers that can be shared/included in a policy package.
Yes.
From R80.40, the HTTPS Inspection policy as a layer that can be either reused or unique for a given policy package.
OpenStack is, Openshift is not directly. You can use it with Generic Data Center object, as described during the session.
At enforcement time. It’s using the same infrastructure as Identity Awareness.
We have an auto-updatable SmartConsole in EA for R81.
Changing the file system requires a new install from scratch. Upgrade in place will keep the “old” file system. The kernel will upgrade with the new version.
Logs can be queried via API in R81. For a continuous stream, we have Log Exporter (exports via syslog).
We have improved the processes on both the gateway and management, which is why this requires R81_ on both the gateway and management.
R80.40 is still considered the "widely recommended" release at this time. R81 is GA quality and can be upgraded to if you need specific functionality. Release recommendation is generally based on customer adoption/feedback as well as jumbo hotfix availability.
The majority of the functionality in the legacy SmartUpdate client is now in R81 SmartConsole for both license and package deployment. Contract deployment in offline environments will be added in later releases.
SMB appliances running R77.20 and regular appliances running R77.30 can be managed from R81. Refer to the R81 Release Notes for the complete list.
Yes, this should work with pre-R81 gateways.
Yes
Yes, JHF installation is available both from SmartConsole and via APIs
No. if you need it, please work with your local office.
No, one by one, standby node is done first.
Not currently.
It is available in EA form.
Please check with your local Check Point office.
The limit is per management domain, regardless of the number of admins.
Subject to the limitations of the Accelerated Policy Installation, yes.
Yes.
Not initially, but we plan to add support for it in the first R81 JHF.
SmartConsole only supports simpler scenarios. For more complex scenarios, it is better to use CDT.
Yes, it is leveraging the same auto-updating infrastructure as other parts of our product.
No, this leverages the same multi-portal infrastructure that is used in the product to allow multiple portals to use the same IP on different URLs.
Refer to the R81 Release SK.
Not in the immediate plans.
Please raise this requirement with your local office.
Initially, it will be supported as a read-only client, but we will add read-write support soon.
Note that features available on the web-based SmartConsole will be limited by API support, so a handful of features will not be available.
We will address these gaps over time.
In environments with Internet access, yes.
Some environments are airgapped from the Internet and those are not automatically updated.
Support for Strongswan was added as part of R81.
is the performance impacted on the mgmt server when using a web browser instead of the smartconsole?
how much of the task is actually done locally on the machine running the smartconsole today?
Regards
magnus
In the old days, some work was done on the client side.
This may still be the case with a few legacy items in SmartConsole, but most of the work done client-side in R8x is rendering the data and querying the API.
This should also apply to the web-based SmartConsole.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY