Introduction to Check Point SASE

Check Point SASE is a cloud-based Secure Access Service Edge (SASE) solution that provides secure private and internet access to your remote and branch office users.

Private Access

Private access includes:

  • Complete Zero-Trust Network Access to all your corporate resources (on-premises and cloud data centers) to your remote or office workforce.

  • Agentless access to only specific applications only to authorized members (also known as Application Access), for example, users with BYOD and contractors. The supported types of applications include:

    Protocol

    Sample Application

    HTTP/HTTPS

    Bitbucket

    RDP

    My Desktop

    SSH

    Staging Web Server

    VNC

    Build PC

Internet Access

Internet access includes safe access to all the web traffic to to your remote or office workforce.

SASE Agent

SASE Agent is an application that is installed on desktops or mobile devices to enforce safe private and internet access.

Note - The agent is not required for application access.

Supported Devices and Operating Systems

Operating System

Version

Downloaded File

Windows EXE Windows 11
Windows MSI Windows 11
macOS macOS 13 or later PKG
Ubuntu

Ubuntu 20.04 or later

Deb

Red Hat

Red Hat 8 or later

 

RPM

Fedora

Fedora 40 or later

 

RPM (Fedora)

Linux - Others

Linux 8 or later

tar.xz

Android / Chromebook1 Android 12.1 or later

Google Play Store.

iOS iOS 15 or later App Store.

How it Works

SASE's cloud-gateway integrates with your SD-WAN (edge) devices in your branch offices or data centers. Its primary function is to process the private access rules, such as firewall rules and application rules. This gateway connects to the SASE Agent to provide a secure full network access. It also connects to a web portal (agentless) to provide secure application access.

For secure internet access, the SASE uses the in-built Secure Web Gateway (SWG) equipped with a Malware Protection Engine (On-device Network Protection capability) in the SASE Agent to process the Access Policy without requiring a separate gateway.

Use Cases

  • You want to provide secure internet access to your remote workforce.

  • You want to provide zero-trust network access to your remote workforce.

  • You want to provide secure access to only particular corporate applications (not entire private access) to your temporary workforce, such as contractors.

  • You want to provide both secure internet and private access to your workforce operating from your offices.

Benefits

  • Easy-to-deploy SASE solution.

  • 2x faster internet security with on-device protection.

  • Improved privacy

  • Accurate location services

  • Web filtering

  • Malware protection and traffic inspection

  • Automatically detect and protect non-secure WiFi traffic

  • Zero-trust access to network and SaaS

  • Full mesh any-to-any connectivity to your private network.

  • A SASE solution that also integrates with your on-premises or cloud SD-WAN infrastructure.

  • Secure access to internal corporate applications (SSH, RDP, Web, Tunnel, and Database) residing in the data center, public or private clouds. Ideal for BYOD and third-party users with no agent installation or management required.

Data Residency

Data residency refers to the physical location where your data is stored and managed.

Data residency encompasses management plane and user information, which includes policy rules, settings, logs, and reports.

SASE supports data residency in these regions:

  • EU

  • US

  • Australia

  • India

  • Canada

Note - Data Residency in EU ensures that data processing and storage occur entirely within the EU and it meets GDPR requirements for data storage and processing.

API Support

You can use SASE API to create, manage, and control network security aspects, including networks, gateways, regions, tunnels, users, and groups.

For more information about SASE API, see app.swaggerhub.com.