UserCheck in the Threat Prevention Policy

This section describes how to configure and use UserCheckClosed Functionality in a Check Point Firewall and endpoint clients that gives users a warning when there is a potential risk of data loss or security violation. This helps users to prevent security incidents and to learn about the organizational security policy..

Watch the Video

When you enable the UserCheck feature, the Security Gateway sends messages to users about possible non-compliant behavior or dangerous Internet browsing, based on the rules an administrator configured in the Security PolicyClosed Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection.. This helps users prevent security incidents and learn about the organizational security policy. You can develop an effective policy based on logged user responses. Create UserCheck objects and use them in the Rule BaseClosed All rules configured in a given Security Policy. Synonym: Rulebase., to communicate with the users.

UserCheck messages are available for these Software Blades:

Limitations

When processing a file over HTTP, UserCheck cannot send messages to the browser after the download started:

  • For newly identified malicious files, the UserCheck Agent is required to display the UserCheck notification.

  • For files already known to be malicious by Threat Emulation, the UserCheck messages can be displayed in the browser.

The SMTP protocol does not provide a user interface for displaying UserCheck messages:

Configuration

Getting Started with UserCheck for Threat Prevention Software Blades:

  1. In the Security Gateway / ClusterClosed Two or more Check Point Firewalls that work together in a redundant configuration - High Availability, or Load Sharing. object:

    1. Enable the applicable Threat Prevention Software Blades.

    2. Configure the applicable UserCheck settings.

      See Configuring UserCheck.

    3. Optional: Download the UserCheck Client and install it on endpoint computers.

      See the R82 Security Gateway Guide > Chapter "UserCheck Client".

  2. Optional: In the Global Properties, configure the applicable UserCheck settings.

  3. Configure the applicable UserCheck Interaction Objects.

    See UserCheck Interaction Objects for Threat Prevention Software Blades.

  4. Configure the applicable Threat Prevention Profiles and Threat Prevention Policy.

    See:

    In Threat Prevention Profiles > click the applicable Software BladeClosed Specific security solution (module): (1) On a Check Point Firewall, each Software Blade inspects specific characteristics of the traffic (2) On a Management Server, each Software Blade enables different management capabilities. page > in the section UserCheck Settings, click the applicable field Prevent or Ask > select the required UserCheck Interaction object.

  5. Install the Threat Prevention Policy on the Security Gateway / Cluster object.

  6. Additional Configuration: