Recommendations to others considering Check Point Multi-Domain Security Management:
You need to pay additional support for MDS environment. For the migration task I recommend to get PS or partner support from the Checkpoint. Buy dedicated high-end newest appliances of Checkpoint for MDS. I won’t recommend MDS running on ESX server. Divide MDS and MLM. MLM needs high-performance I/O, cpu and memory. Install the latest MDS Software version if you start from scratch. Divide the CMAs based on needs and security policies of their own. Backup MDS daily. If you have a problem on the CMA you cannot restore the single CMA; you need to restore the MDS. Avoid using the opsec lea for 3rd party logging systems, log exporter is much better and gives high performance. Use Global policy with caution. Consistently enforce firewall administrators to connect to MDS with the latest smartconsole applications. Apply HFAs regularly. Don’t store too many revisions on the CMAs. Otherwise you’ll get issues in backup and migration. Periodically maintain the rule bases and objects/services. Review collected by and hosted on G2.com.
What problems is Check Point Multi-Domain Security Management solving and how is that benefiting you?
The main reason, we had switched over Security Management server (SMS) to a Multi Domain Security Management (MDS- old name is Provider-1) is the limitation of multiple admins working on the security policy. Admin is locking the SMS with write policy; other administrators can only work in read only mode to see the logs and status. With R80 it’s much more granular to operate the policy, administrators can now only lock the rules they’re working, and admins cannot lock the entire policy. With the MDS firewall administrators can use a single smartconsole to operate and manage the firewalls. Central smart log on the MDS level assists the firewall administrators in addressing the policy-related issues. The single pane of Smart Event and logging gives full Threat visibility; even the SOC team uses smart console and login to MDS to get more relevant information related to threat hunting and incident management. Integration with 3rd party tools works smoothly through the MDS. Auditors use the MDS to get administrative details. Review collected by and hosted on G2.com.