
Welcome to the sixth article, concluding our series on the Check Point SandBlast Agent Management Platform. In this series, we have covered the key aspects of deploying and administering SandBlast Agent using the Management Platform. In this article, we will attempt to answer the most frequently asked questions related to the Management Platform solution and explain how to test the SandBlast Agent Management Platform with our assistance completely free of charge.
All articles in the series about SandBlast Agent Management Platform:
FAQ
Currently, there are not many sources of information about the SandBlast Agent Management Platform, the main ones being: , sections and on CheckMates. Therefore, we decided to answer the most common questions about the SandBlast Agent Management Platform that administrators have when considering this product as a solution for protecting employees' personal workstations. A very detailed FAQ on SandBlast Agent can also be found in .
1. What is the difference between SandBlast Agent Management Platform and SandBlast Agent Cloud Management?
The SandBlast Agent Cloud Management solution is a predecessor to the Management Platform and allows for the deployment of a cloud management server for agents in the Check Point infrastructure, which can then be managed using SmartConsole. This is a convenient option that does not require the organization to spend resources on deploying a virtual management server or installing a physical device; however, a limitation is that SmartConsole requires installation on the administrator's computer and is only available for Windows. Currently, Check Point recommends the SandBlast Agent Management Platform as the primary solution for cloud administration of agents, as evidenced by the informational message when attempting to create a SandBlast Agent Cloud Management application on the Infinity Portal.
2. How is the SandBlast Agent Management Platform licensed?
No license is required to use the SandBlast Agent Management Platform; the ability to deploy the application in the Infinity Portal for managing agents is granted even with the purchase of a single SandBlast Agent license. It is also worth noting that when registering an account in the Infinity Portal, a temporary license for 30 days is provided, after which a valid license for the SandBlast Agent must be used. The verification of the valid license is done automatically without the administrator's involvement — it is enough to link the Check Point account to the Infinity Portal in the Global Settings → Contracts → Associated Accounts section.
3. How is the SandBlast Agent licensed?
There are several specifications of the SandBlast Agent, differing in the set of blades suitable for various user machine protection tasks. Below is a table from the official site , demonstrating the differences in the current specifications of the SandBlast Agent. After choosing the appropriate specification, licensing is carried out for the required number of end devices.
4. Which operating systems are supported for installing the SandBlast Agent?
Currently, the latest version of the SandBlast Agent is available for Windows (7, 8, 10), Windows Server (2008 R2, 2012 R2, 2012, 2016, 2019), and macOS (10.14, 10.15). Recently, Check Point also announced the release of a beta version for Linux, which we covered in the . Current information about the recent releases of the SandBlast Agent can always be found in . In addition, you can follow the schedule of past and upcoming releases of the SandBlast Agent in .
5. Can agents be managed using the Management Platform and SmartEndpoint?
When deploying agents via the Management Platform service, management is also supported through the "classic" SmartEndpoint console, which can be downloaded from the Service Management section. However, at present, there is no full backward compatibility between the settings of the Management Platform and SmartEndpoint, and conflicts may arise when administering agents using both consoles simultaneously. This is primarily due to the use of a unified Threat Prevention policy (known as Unified Policy) in the Management Platform, where all security components are consolidated into a single policy. In the Management Platform, you can set up a view of the settings compatible with SmartEndpoint — for this, you need to select 'User based Policy' in the Endpoint Settings → Policy Operation Mode section. The Gaia R81 version will have a web interface identical to the Management Platform, but at this time, it is recommended to use one management tool for agents to avoid configuration conflicts.
How to test the SandBlast Agent Management Platform?
You can test the SandBlast Agent Management Platform solution independently or by contacting a partner for a complete pilot project. For independent testing, simply register on the Infinity Portal following the instructions from our , at which point a temporary license for one month will be automatically created for the administration of 100 user machines.
The second option is to deploy and test the SandBlast Agent Management Platform as part of a pilot project conducted in collaboration with an engineer from Check Point's partner company. The pilot project is completely free and aims to demonstrate the product's capabilities with the option of consultations from qualified experts. For questions regarding the pilot project for the SandBlast Agent Management Platform, you can contact us at .
In conclusion
In the series of articles on the SandBlast Agent Management Platform, we have tried to highlight the main features of the solution and demonstrate the configuration of important security components through specific examples. We would be happy to answer any questions about the product in the comments.
. To not miss new publications, follow updates on our social media (, , , , ).
Source: habr.com
