Recommended Deployment - DLP Gateway with Mail Relay
Item |
Description |
---|---|
1 |
Internal mail server |
2 |
DLP Gateway |
3 |
Mail relay in the DMZ |
Make sure that the DLP Gateway does NOT scan emails as they pass from the mail relay to the target mail server in the Internet.
-
In SmartConsole Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., click Gateways & Servers and double-click the Security Gateway Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources..
The gateway window opens and shows the General Properties page.
-
Make sure that mails from the internal mail server (e.g. Microsoft Exchange) (1) arrive at the gateway using an internal Gateway interface.
-
From the navigation tree, click Network Management.
-
Double-click the gateway interface that leads to the internal mail server.
-
From the General page, click Modify.
-
In the Leads To section, click Override > This Network (Internal) > Network defined by the interface IP and Net Mask.
-
Click OK and close the interface window.
-
-
Deploy the internal mail relay (2) behind a DMZ interface of the DLP Gateway:
In the Topology page of the DLP Gateway object, define the gateway interface that leads to the Mail relay as Internal and also as Interface leads to DMZ.
-
In the Networks section of the My Organization page:
-
Select Anything behind the internal interfaces of my DLP Gateways
-
Do NOT select Anything behind interfaces which are marked as leading to the DMZ
-
|
Note - If the DLP Gateway interface leading to the internal mail relay is internal, and you cannot deploy the internal mail relay behind a DMZ interface of the DLP Gateway. |
-
In SmartConsole, select Security Policies > Shared Policies > DLP and click Open DLP Policy in SmartDashboard.
SmartDashboard Legacy Check Point GUI client used to create and manage the security settings in versions R77.30 and lower. In versions R80.X and higher is still used to configure specific legacy settings. opens and shows the DLP tab.
-
From the navigation tree, click My Organization page.
-
In the Networks section, click Select specific networks and hosts.
-
Click Edit.
-
Select the networks that include the internal mail server, but do NOT include the relay server.
-
Click OK.
-
Click Save and then close SmartDashboard.
-
In SmartConsole, install policy.