- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
On 4th September 2019, we did a TechTalk with @Tomer_Sole on Check Point's new security solutions for SD-WAN.
We talked briefly about CloudGuard Edge for SD-WAN devices, but mostly discussed CloudGuard Connect, Cloud Network Security as a Service.
Materials available to CheckMates members:
Selected questions asked during the session, with some answers.
Yes
Yes, but the documentation is not currently published. Please contact us and we can provide it.
When a site is created, it is created in two distinct datacenters in the same region. You can create another site in a different region, but there is no automatic failover.
Not currently.
Not currently.
Not currently, but these use cases are planned for the future.
We have a different solution for roaming users currently called Capsule Connect that we plan to fold into CloudGuard Connect in the near future.
Yes
In the near-term roadmap.
Not currently.
Using on-premise identity sources? Not currently. A number of cloud-based Identity Providers, including ADFS, are supported.
All traffic is sent.
I think you posted the wrong link to the full video.
Cheers,
David
Hmm my fault then - I was confused about the different titles where one contains "security" and the other "connect" 😳
The link does not go to the full video. I get to the same page with a video excerpt.
I can't download the presentation, I get "Please contact your administrator with the following error code: 1DD4E4D2"
Had the wrong links above, this should be fixed @Olga_Kuts @Alex-
@PhoneBoy Got it, many thanks!
Will you also provide a video replay fuction, where I can change the replay speed ?
Few more questions and answers:
CloudGuard Edge is installed per edge device. With CloudGuard Connect, you configure which location is closest to your office. Assuming that the office doesn't move, this should work. Roaming users can use Capsule Cloud until this functionality gets integrated within CloudGuard Connect.
The two tunnels per branch device go to different data centers in the same region.
Currently, only PSK authentication is supported. Note that none of the popular SD-WAN solutions support certificate-based authentication currently. If this is a requirement, please contact us.
Yes, Check Point SMB devices are supported. Step-by-step instructions exist on the Infinity Portal.
Currently it is 850mbps per site object. You can split your subnets at the same branch office into multiple site objects on the Infinity Portal.
A formal document will be made available shortly, but the SLA is 99.999% thanks to our public cloud infrastructure and reliable mature security products.
This is a function provided by most SD-WAN Edge Devices. It is configured on the device, not in CloudGuard Connect.
You mentioned briefly the CloudGuard Edge solution.
How does you solution match/respond on the trend of having a local breakout to the cloud ?
For example with Office 365 the local breakout is recommended.
a) does/how does Cloud Guard Edge provide this architecture feature of a local breakout ?
b) Is Cloud Guard Connect the recommended architecture because of more implemented security features than with Cloud Guard Edge only ?
c) Is this a balancing act, like on the one side I would have a local breakout for better quality, on the other side I will have more security but a centralized breakout maybe due to network constraints with not so good quality.
d) Does Cloud Guard Connect also provide performance data ? Or should I start the typical implementation of performance measurment on the edge e.g. when SD-WAN boxes provide performance data ?
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY