Connectivity from VS0 and subsequent VS’s when communicating with the proxy for updates
More actions
Reference behaviour for update connectivity from VS0 and individual Virtual Systems when a proxy is used.
Question
What is the expected behaviour of proxy connectivity from VS0 and subsequent Virtual Systems when communicating with the proxy for updates? In particular, if VS0 loses update connectivity and individual Virtual Systems obtain updates directly, what happens when VS0 connectivity returns?
Behaviour by blade
IPS
IPS updates are performed from management during policy installation and are handled per Virtual System.
AntiVirus and AntiBot
VS0 downloads the update and each Virtual System uses it.
If VS0 cannot download an update, for example because it has no Internet connectivity, other Virtual Systems can download that update themselves. This is evaluated for each update individually, so VS0 attempts the next update again.
URL Filtering and Application Control
VS0 must have Internet connectivity to obtain the Application Control and URL Filtering database. If VS0 cannot obtain the data, the individual Virtual Systems do not independently download it.
Proxy configuration
When proxy servers are used, a proxy can be defined for each Virtual System through SDB for Check Point products. Updates performed per Virtual System use those proxy definitions.