UserCheck in the Threat Prevention Policy
This section describes how to configure and use UserCheck
Functionality in a Check Point Firewall and endpoint clients that gives users a warning when there is a potential risk of data loss or security violation. This helps users to prevent security incidents and to learn about the organizational security policy..
Watch the Video
When you enable the UserCheck feature, the Security Gateway sends messages to users about possible non-compliant behavior or dangerous Internet browsing, based on the rules an administrator configured in the Security Policy
Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection.. This helps users prevent security incidents and learn about the organizational security policy. You can develop an effective policy based on logged user responses. Create UserCheck objects and use them in the Rule Base
All rules configured in a given Security Policy. Synonym: Rulebase., to communicate with the users.
UserCheck messages are available for these Software Blades:
-
Access Control:
-
Threat Prevention:
Limitations
When processing a file over HTTP, UserCheck cannot send messages to the browser after the download started:
-
For newly identified malicious files, the UserCheck Agent is required to display the UserCheck notification.
-
For files already known to be malicious by Threat Emulation, the UserCheck messages can be displayed in the browser.
The SMTP protocol does not provide a user interface for displaying UserCheck messages:
-
For the Anti-Virus, IPS
Software Blade on a Check Point Firewall that inspects and analyzes packets and data for numerous types of risks (Intrusion Prevention System). and Threat Emulation blades - The UserCheck agent is supported only when a client uses SMTP to send an email through the SMTP server. -
Sending UserCheck notifications through email is not supported for Anti-Virus, IPS and Threat Emulation.
-
For the Threat Emulation and Anti-Virus blades - To provide user-friendly notifications over email, configure the Security Gateway as a Mail Transfer Agent
Feature on a Check Point Firewall that intercepts SMTP traffic and forwards it to the applicable inspection component. Acronym: MTA. - When a malicious attachment is detected, it is replaced with a text file.
Configuration
Getting Started with UserCheck for Threat Prevention Software Blades:
-
In the Security Gateway / Cluster
Two or more Check Point Firewalls that work together in a redundant configuration - High Availability, or Load Sharing. object:-
Enable the applicable Threat Prevention Software Blades.
-
Configure the applicable UserCheck settings.
-
Optional: Download the UserCheck Client and install it on endpoint computers.
See the R82 Security Gateway Guide > Chapter "UserCheck Client".
-
-
Optional: In the Global Properties, configure the applicable UserCheck settings.
-
Configure the applicable UserCheck Interaction Objects.
See UserCheck Interaction Objects for Threat Prevention Software Blades.
-
Configure the applicable Threat Prevention Profiles and Threat Prevention Policy.
See:
In Threat Prevention Profiles > click the applicable Software Blade
Specific security solution (module): (1) On a Check Point Firewall, each Software Blade inspects specific characteristics of the traffic (2) On a Management Server, each Software Blade enables different management capabilities. page > in the section UserCheck Settings, click the applicable field Prevent or Ask > select the required UserCheck Interaction object. -
Install the Threat Prevention Policy on the Security Gateway / Cluster object.
-
Additional Configuration: