Security Gateways and Security Management Server require access to the Internet (either directly, or via configured proxy) for various Software Blades. The table below lists the relevant connectivity tests.
For each of the curl_cli commands, add the option --cacert $CPDIR/conf/ca-bundle.crt to prevent the issue in sk110779.
In Gaia Embedded OS, use the "wget" command. It is enough to check the connectivity only to the http://cws.checkpoint.com server. Use the following syntax: [Expert@HostName:0]# [http_proxy=Proxy_IP_or_HostName:Port] wget http://cws.checkpoint.com/
In SecurePlatform OS, use the "curl" command instead of "curl_cli" command.
If IPv6 address is assigned on Security Gateway / Security Management Server, then these services should be allowed in the rulebase for IPv6 as well.
All the domains below are part of the new Updatable object “Check Point Services”. For more information on Updatable objects, see sk131852.
Push Notifications (since R77.10) for incoming e-mails and meeting requests on hand held devices, while the Capsule Workspace Mail app is in the background
curl -vk https://push.checkpoint.com/push/ping
downloads.checkpoint.com
http
Mobile Access Gateway, Security Management Server
Download of Endpoint Compliance Updates (Endpoint Security On Demand (ESOD) database):
Core file uploader is using this services. ( Authentication/Upload backend )
curl -vk https://diag-services.checkpoint.com
Additional Notes:
Specific IP addresses for the servers are not provided because they vary by region and are subject to change.
There are some Check Point Services / Software Blades that requires Proxy configuration on top of the Proxy global property configured in the object of your Security Management Server / Domain Management Server, so that connections to sigcheck.checkpoint.com will be able to pass through your Proxy server.
Examples from R7X SmartDashboard:
Note: Check if you have one those blades enabled and configure proxy settings for each of them.
Endpoint Compliance
Go to the "Mobile Access" tab
Expand the "Endpoint Security On Demand"
Click on the "Endpoint Compliance Updates"
In the "Automatic Update" section, click on the "Configure..." button
Go to the "Proxy" tab
Example:
Legacy URL Filtering
Go to the "Application & URL Filtering" tab
Expand the "Legacy URL Filtering"
Click on the "Legacy URL Filtering Policy"
Click on the "Automatic updates" link
Go to the "Proxy" tab
Example:
Traditional Anti-Virus and Edge devices
Go to the "Threat Prevention" tab
Expand the "Traditional Anti-Virus"
Click on the "Database Updates"
In the "Automatic Update" section, click on the "Configure..." button
Added information about Proxy configuration on top of the Proxy global property configured in the object of Security Management Server / Domain Management Server
25 Apr 2017
Added http://downloads.checkpoint.com
16 Feb 2017
Added "Revision History" section
02 Mar 2017
Added teadv.checkpoint.com
Give us Feedback
Thanks for your feedback!
Are you sure you want to rate this stars?