Greetings,
Does anyone know how to successfully apply and run Autonomous Threat Prevention on Security Gateways with only an NGTP license?
According to sk163593, you don't need a full NGTX/SBNT license to use Autonomous Threat Prevention:
https://support.checkpoint.com/results/sk/sk163593
And that is indeed the case. Autonomous Threat Prevention works just fine with NGTP, but Smart Console constantly complains about the Security Gateway not having a valid Threat Emulation or Threat Extraction license.
This makes sense as we are running the "Perimeter (recommended)" profile in the Autonomous Threat Prevention Policy, which tries to enable and utilise both Threat Emulation and Threat Extraction.
But there seems to be no way for us to disable these blades. You can't choose what blades to run on the Security Gateway object. You choose Autonomous Threat Prevention or Custom Threat Prevention, which lets you manually select blades.
No apparent settings within the Autonomous Threat Prevention Policy let you disable specific blades. The closest thing I've found is to go to Autonomous Policy -> Settings -> Advanced Settings and add Sandbox and Sanitization with "Off" as an override. But this doesn't change anything regarding Smart Console complaining about no valid Threat Emulation or Threat Extraction license on the Security Gateway.
I even tried to create a global exception disabling both blades in the policy. But it's still complaining. I tried to re-create this in my LAB, and it's the same behaviour. I can't locate any meaningful information in the ATRG SK for Autonomous Threat Prevention or anything in the R81.10 or R81.20 Threat Prevention Administration Guides.
How is one expected to deploy and run Autonomous Threat Prevention with only NGTP and no NGTX/SBNT license on the Security Gateway? Do you have to ignore the red warning on the object in Smart Console??
Certifications: CCSA, CCSE, CCSM, CCSM ELITE, CCTA, CCTE, CCVS, CCME