Document toolboxDocument toolbox

(v2.2) Check Point Sandblast Cloud settings

In the Check Point SandBlast settings dialog it is possible to change the following settings concerning Check Point SandBlast Cloud detection engine:

Maximum file size limit

Specifies the maximum file size for which to perform the check by the engine.

Treat oversize as clean

If this is enabled and the check is skipped because the file is too big, the file is considered “clean” (like if the check was performed and found no problems). If this is disabled, then such file is considered “suspicious/dangerous” (like if the check was performed and found a problem) and the whole package will be quarantined.

Block following ratings

The result of a check by the sandbox engine can in case of new unknown threats be one of the following values:

  • Low risk

  • Medium risk

  • High risk

This setting specifies, which of these results are treated as dangerous and will be blocked (quarantined). It is recommended to block medium and high risk results. Low risk is to be considered, as it can be more often a “false positive” result.

Remote access mode

Specifies whether to use HTTP or HTTPS to access the Check Point SandBlast API. HTTP should be used only in internal networks.

IP address or DNS hostname

IP address or hosname of the Check Point SandBlast.

TCP port

TCP port on which the Check Point SandBlast HTTP(S) interface runs.

API key

Sets the API key which will be used when accessing the Check Point SandBlast.

Images

UUID of the system image which will be used to perform the file checks. The current list of available images should be documented HERE.

Test

Using the Test button it is possible to test the access to the Check Point SandBlast using the parameters entered above and verify if it works.