4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

Welcome to the fourth article in the series on the Check Point SandBlast Agent Management Platform. In previous articles (One, Two, Three) we detailed the interface and capabilities of the management web console, as well as reviewed the Threat Prevention policy and tested it against various threats. This article is dedicated to the second security component — the Data Protection policy, which is responsible for protecting data stored on the user's machine. We will also cover the Deployment and Global Policy Settings sections in this article.

Data Protection Policy

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

The Data Protection Policy allows access to data stored on the workstation only for authorized users, using full disk encryption (Full Disk Encryption) and boot protection (Boot Protection). Currently, the following disk encryption configurations are supported: for Windows — Check Point Encryption or BitLocker Encryption, and for MacOS — File Vault. Let’s take a deeper look at the capabilities and settings of each option.

Check Point Encryption

Check Point Encryption is the standard disk encryption method in the Data Protection policy and provides encryption of all system files (temporary, system, removable) in the background without affecting the workstation's performance. Once encrypted, the disk becomes inaccessible to unauthorized users.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

The main setting for Check Point Encryption is 'Enable Pre-boot', which requires user authentication before the operating system loads. This option is recommended as it prevents the use of authentication bypass methods at the operating system level. There are also options to configure temporary bypass settings for the Pre-boot function:

  • Allow OS login after temporary bypass — disables the Pre-boot function and switches to authentication within the operating system;

  • Allow pre-boot bypass (Wake On LAN – WOL) — disables the pre-boot function on computers connected to the management server via Ethernet;

  • Allow bypass script — allows configuring the Pre-boot bypass with specified start time and date for the script and parameters for ending the Pre-boot bypass;

  • Allow LAN bypass — disables the pre-boot function when connected to a local network.

The options for temporarily bypassing the Pre-boot function mentioned above are not recommended to be used without explicit reasons (for example, technical work or troubleshooting), and the best solution from a security standpoint is to enable the Pre-boot function without specifying temporary bypass rules. If it is necessary to bypass Pre-boot, it is recommended to set the minimum required timeframe in the temporary bypass settings to avoid reducing the level of protection for an extended period.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

Additionally, when using Check Point Encryption, there is the ability to configure advanced settings for the Data Protection policy, such as more flexible encryption parameter configurations, as well as adjustments to various aspects of the Pre-boot function and Windows authentication.

BitLocker Encryption

BitLocker is part of the Windows operating system and allows for the encryption of hard disks and removable storage devices. Check Point BitLocker Management is a component of Windows services that automatically starts with the SandBlast Agent client and uses APIs to manage BitLocker technology.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

When selecting BitLocker Encryption as the disk encryption method in the Data Protection policy, the following parameters can be configured:

  • Initial Encryption — initial encryption settings, allows encrypting the entire drive (Encrypt entire drive), which is recommended for machines with existing user data (files, documents, etc.), or encrypting only the data (Encrypt used disk space only), which is recommended for new installations of Windows;

  • Drives to encrypt — selection of drives/partitions for encryption, allows encrypting all drives (All drives) or just the partition with the operating system (OS drive only);

  • Encryption algorithm — choice of encryption algorithm, the recommended option is Windows Default, with the possibility to specify XTS-AES-128 or XTS-AES-256.

File Vault

File Vault is Apple's standard encryption tool and ensures that only authorized users have access to the data on the user's computer. With File Vault enabled, users must enter a password to start the system and gain access to encrypted files. Using File Vault is the only way to ensure data protection in the Data Protection policy for users of the MacOS operating system.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

For File Vault, the setting "Enable automatic user acquisition" is available, which requires user authorization before the disk encryption process begins. If this function is enabled, it is possible to specify the number of users who must be authorized before the SandBlast Agent applies the Pre-boot feature, or specify the number of days after which the Pre-boot feature will be automatically implemented for all authorized users if at least one user has logged into the system during this period.

Data Recovery

In case of system boot issues, various data recovery methods can be employed. The administrator can initiate the recovery process of encrypted data from the Computer Management → Full Disk Encryption Actions section. When using Check Point Encryption, it is possible to decrypt a previously encrypted disk and gain access to all stored files. After this procedure, the disk encryption process must be restarted for the Data Protection policy to work.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

When selecting BitLocker as the disk encryption method for data recovery, it is necessary to enter the Recovery Key ID of the problematic computer to generate the Recovery Key, which must then be entered by the user to access the encrypted disk.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

For MacOS users utilizing File Vault for protecting stored information, the recovery process involves generating a Recovery Key by the administrator based on the Serial Number of the problematic machine and entering this key followed by a password reset.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

Deployment Policy

Since the release of the second article, which discussed the web management console interface, Check Point has made some changes in the Deployment section—now it includes the sub-section Software Deployment, where configuration (enabling/disabling blades) for already installed agents is set up, and the sub-section Export Package, where packages with pre-installed blades can be created for further installation on user machines, for example, using Active Directory group policies. Let's consider the Software Deployment sub-section, where all SandBlast Agent blades are enabled.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

I would like to remind you that the standard Deployment policy only includes blades from the Threat Prevention category. Considering the previously discussed Data Protection policy, it is now possible to enable this category for installation and operation on the client machine with the SandBlast Agent. It makes sense to enable the Remote Access VPN feature, which will allow users to connect, for instance, to the organization’s corporate network, as well as the Access and Compliance category, which includes Firewall & Application Control functionalities and checking the user's machine for compliance with the Compliance policy.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

Export Package
4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

The Export Packages section is extremely simple to use: to create a configuration package, you need to specify its name, select the operating system (for Windows, also specify the architecture), and the version of the agent, after which you choose the security policies to be embedded in the package. Additionally, you can specify a virtual group that will include computers with the installed package, as well as select a VPN Site with preconfigured connection addresses and authentication parameters (VPN Sites are configured in the Export Packages → Manage VPN Sites section). The last point is particularly convenient as it eliminates the possibility of user error when configuring VPN connection parameters.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

Global Policy Settings

In the Global Policy Settings, one of the most important parameters is configured—the password for removing the SandBlast Agent from the user’s machine. After installing the agent, the user will not be able to remove it without entering the password, which by default is the word "secret" (without quotes). However, this default password is easy to find in public sources, and when implementing the SandBlast Agent solution, it is recommended to change the default password for agent removal. In the Management Platform, with the default password, the policy can only be set 5 times, so changing the removal password is inevitable.
Additionally, in the Global Policy Settings, the parameters of the data that can be sent to Check Point for analysis and improvement of the ThreatCloud service are configured.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

In the Global Policy Settings, some disk encryption policy parameters are also configured, namely password requirements: complexity, duration of use, ability to use a previously valid password, and more. In this section, you can upload your own images instead of the standard ones for Pre-boot or OneCheck.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

Policy installation

After reviewing the capabilities of the Data Protection policy and configuring the appropriate settings in the Deployment section, you can proceed with installing a new policy that includes disk encryption using Check Point Encryption and other SandBlast Agent blades. After the policy is installed in the Management Platform, the client will receive a message about the need to install the new version of the policy now or to postpone the installation for another time (up to 2 days).

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

Once the download and installation of the new policy are complete, SandBlast Agent will prompt the user to restart the computer to enable Full Disk Encryption protection.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

After rebooting, the user will need to enter their credentials in the Check Point Endpoint Security authentication window — this window will appear every time before the operating system starts (Pre-boot). There is an option to select Single Sign-On (SSO) for automatic use of credentials during authentication in Windows.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

In case of successful authentication, the user gains access to their system while in the background, the disk encryption process begins. This operation does not affect the machine's functionality, although it may take a long time (depending on the volume of disk space). Once the encryption process is complete, we can confirm that all blades are enabled and functioning, the disk is encrypted, and the user's machine is protected.

4. Check Point SandBlast Agent Management Platform. Data Protection Policy. Deployment and Global Policy Settings

Conclusion

In summary: in this article, we examined the capabilities of SandBlast Agent for protecting information stored on the user's machine through disk encryption in the Data Protection policy, explored the settings for policy dissemination and agents through the Deployment section, and installed a new policy with disk encryption rules and additional blades on the user's machine. In the next article of the series, we will take an in-depth look at the logging and reporting capabilities in the Management Platform and the SandBlast Agent client.

A large collection of materials on Check Point from TS Solution. To not miss the next publications on the SandBlast Agent Management Platform — follow our updates on social media (Telegram, Facebook, VK, TS Solution Blog, Yandex.Zen).

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster