Check Point Gaia R81 is now EA. first look

Check Point Gaia R81 is now EA. first look

A new version of Gaia R81 has been released to Early Access (EA). Previously, you could see planned innovations in release notes. Now we have the opportunity to see it in real life. For this, a standard scheme was assembled with a dedicated management server and a gateway. Naturally, we did not have time to conduct all the full-fledged tests, but we are ready to share what immediately catches your eye when you get acquainted with the new system. Under the cut are the main points that we highlighted when we first met the system (a lot of pictures).

Management

When you initialize the gateway, you have the opportunity to immediately connect to the cloud management server - Smart 1 Cloud (so-called MaaS):

Check Point Gaia R81 is now EA. first look
This is a relatively new feature (there is also in the latest 80.40 takes) and we will tell you a little more about this service in the most soon. Here, the main plus (in our opinion) is the long-awaited ability to control through the browser πŸ™‚

VxLAN and GRE

The first thing we β€œclimbed” to check was support for VxLAN and GRE. Release Notes did not deceive us, everything is in place:

Check Point Gaia R81 is now EA. first look

You can argue about the need for these features on NGFW, but it's still better when the user has such a choice.

Infinity Threat Prevention

This is probably the first thing that catches your eye when you start to edit the security policy. Added a new activation option for Threat Prevention blades - Infinity. Those. no need to choose which blades to include, Check Point decided everything for us (I don’t know how good it is):

Check Point Gaia R81 is now EA. first look
At the same time, of course, you still have the possibility of the usual self-configuration of the blades.

Infinity Threat Prevention Policy

Since we are talking about Threat Prevention, let's immediately look at Policy. This is probably one of the most significant changes:

Check Point Gaia R81 is now EA. first look

As you can see, there are many more pre-configured policies. You can see in detail what is the difference between them by clicking on Help me decide:

Check Point Gaia R81 is now EA. first look
Check Point Gaia R81 is now EA. first look
Check Point Gaia R81 is now EA. first look

This policy is dynamic and is updated without your participation.

Change Report

Finally, you can see in a convenient form what exactly was changed during configuration editing:

Check Point Gaia R81 is now EA. first look

There is a general report:

Check Point Gaia R81 is now EA. first look

And there are very specific sections:

Check Point Gaia R81 is now EA. first look
Check Point Gaia R81 is now EA. first look

It is very convenient to follow the changes.

Web Management for Endpoint

As you probably know, you can enable Endpoint Management on the management server and manage SandBlast agents. R81 added an interesting feature - browser control. It turns on in a rather interesting way. You need to enter the CLI mode expert and enter the command β€œweb_mgmt_start”, and then go to the address - https://:4434/sba/. And the web console will open in front of you:

Check Point Gaia R81 is now EA. first look

We partially talked about this platform as part of the articles "Check Point SandBlast Agent Management Platform"from Alexey Malko. True, such a console was available there only in the cloud, but now it also works on local management servers.

smart update

When you try to add licenses through the good old Smart Update, the console will kindly warn you that now you can do this without leaving the already familiar Smart Console:

Check Point Gaia R81 is now EA. first look

NAT

The functionality we are expecting. Now in NAT rules you can use Access Roles, Security Zones or Updateable Objects. There are cases when it is very useful and necessary.

Conclusion

That's all for now. There are many more innovations that require testing (IoT, Azure AD, Updgrade, Logs API, etc.). As I wrote above, in the near future we will publish an overview of the new cloud management system - Smart-1 Cloud. Stay tuned for updates in our channels (Telegram, Facebook, VK, TS Solution Blog)!

Also, don't forget about our big a selection of materials on Check Point.

Source: habr.com

Add a comment