Policy Insights

Policy Insights helps administrators analyze and optimize the policy Rule BaseClosed All rules configured in a given Security Policy. Synonym: Rulebase., by offering detailed insights and visualizations. The Check Point Cloud Services analyze traffic and policies and provide suggestions to changing the RuleClosed Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. Base based on this information. The suggestions are generated according to internal scheduling. A cleaner and more efficient Rule Base makes it easier to manage the security policiesClosed Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection., and helps reduce vulnerabilities.

Prerequisites

Supported Objects

Policy Insights supports these objects:

  • In the Source and Destination columns:

    • Hosts

    • Networks

    • Groups

  • Services and Service Groups:

    • icmp

    • icmp6

    • rpc

    • tcp

    • udp

    • dce-rpc

Prerequisites

Connect your Security Management ServerClosed Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. to the Infinity Portal. See To connect from your Security Management Server and Security Gateway objects from SmartConsole to the Infinity Portal for instructions.

Note - There is no need to enable Log Sharing or Configuration Sharing.

Working with Policy Insights

To access the Policy Insights window

  1. In SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., go to the Security Policies view > Access Control > Policy.

  2. Above the Rule Base, click the Insights button.

    The Policy Insights window opens.

Components of the Policy Insights Window

The Policy Insights window is comprised of 3 sections:

In each category in the Policy Insights window, you can see the latest date on which the presented information is based.

The number in each category represents the number of suggestions for this category.

Next to each suggestion, one of these options appears:

  • : Recommended - Suggestions with high security impact and high confidence.

  • No icon - Suggestions with security impact but no conclusive confidence due to limited data.

  • : Low Confidence - Not enough logs and time to have conclusive confidence. For example, new rules, rules that changed recently, or other cases when data is limited.

You can export the information in the Policy Insights window as a CSV file. To do so, click the Export to CSV button, at the bottom left corner of the Policy Insights window.

To see suggestions for a specific rule

  1. In the Access Control policy, select the required rule.

  2. In the bottom pane, click the Insights tab.

  3. Click the Open button to open the Policy Insights window.

  4. In the Policy Insights window, select the required action.

  5. Publish your changes and Install Policy.