CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Internal Security > Endpoint Security (Formerly Integrity)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-12-01
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Experiences with Endpoint Security in large environments

Hello all,

has anyone of you made any experiences yet setting up endpoint security in more advanced environments (5000+ remote users)? I mean with SmartCenter HA and everything. Distributed Endpoint Security Server. Maybe even an Endpoint Security Server cluster. Any technical issues to mention? Anything to consider in preparation of such a task?
Reply With Quote
  #2 (permalink)  
Old 4 Weeks Ago
Senior Member
 
Join Date: 2007-06-22
Posts: 111
Rep Power: 2
CSING has an average reputation (10+)
Default Re: Experiences with Endpoint Security in large environments

A couple of things to be aware of:

1. Integrity 6.5 server can be clustered. The 7.0 CPES server is not clustered or HA. It is more like a hot spare. You must manually switch the active server. However with Office awareness configured this becomes less of an issue.

2. 7.5 will allow multiple active Connection Managers. "Loadbalancing" will be done on the client via a serverlist provided by the Active servers to the client.

3.There is a bug currently with HFA1 such that the serverlist on new remote vpn deployments clients sometimes gets stuck sending syncs to the standby server. The fix is complete and is in the next version.

4. With remote users you will want to consider cooperative enforcement with the gateway. This requires some additional steps that needs to be fully tested in your lab before implementation. All the steps needed are not yet in a single document for 7.0.

5. regarding HA smartcenter servers: never heard of a problem with that. Haven't been involved with a SC HA deployment for CPES but would be very surprised if this had any issue. hth

Last edited by CSING; 4 Weeks Ago at 08:46.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:20.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0