Overview:
In some cases, customers may already have an email protection solution in place. This guide is intended to help ensure a smooth transition to Check Point Email Protection via Guardz. Two different scenarios are defined:
Moving from a gateway filtering solution
Moving from an exiting Check Point Email Protection (Avanan) account
Moving from a Gateway Filtering Solution
Option 1: Start by Completely Disconnect the Gateway
Fully disconnect the gateway:
Ensure all connectors and mail flow rules are removed.
Change the MX records to redirect mail directly to the tenant.
Please Note:
The above are general guidelines for typical gateway configurations. The Gateway vendor’s documentation should be consulted to manage any non standard configurations.
Proceed to install Check Point by following the instructions here:
Option 2: Configure Check Point in Detect & Prevent Mode First, and then Fully Remove the Email Gateway
Proceed to install Check Point by following the instructions here:
Once fully installed, open a support ticket requesting the protection mode policy be set to 'Detect & Prevent' within Avanan. This mode will prevent interference with the gateway while keeping filtering active until the gateway is disabled and MX records changed.
Fully disconnect the old email gateway:
Ensure all connectors and mail flow rules are removed (the inbound connector in particular is important to remove since it typically is configured to only allow mail delivery from the gateway)
Change the MX records to redirect mail directly to the tenant.
Once the gateway is fully disconnected, contact support to switch Check Point back to Inline protection.
Please Note:
The above are general guidelines for typical gateway configurations. The Gateway vendor’s documentation should be consulted to manage any non-standard configurations.
Moving from an Exiting Check Point Email Protection (Avanan) Account to Guardz Integrated Solution
Microsoft 365
Step 1: Fully remove the Current Check Point Instance
Navigate to the Customer Portal for the tenant
Settings > SaaS Applications > Click ‘Stop’ on the mail SaaS application (and any others that are configured).
This will trigger Check Point to uninstall from the tenant.
Delete the tenant from the MSP Dashboard within Check Point (right click on the 3 dots to the far right of the tenant > Delete).
Step 2: Validate Check Point Email Protection has been Fully Removed
Typically, all components are removed after completing the prior steps; however, manual verification is recommended before proceeding with reinstallation.
Delete the Avanan Application within the Cloud tenant.
http://entra.microsoft.com > Enterprise Applications > Click into the Avanan App > Properties > Delete (if it is still present 5-10 minutes after stopping the SaaS application).
Remove Avanan Transport Rules.
admin.exchange.microsoft.com > Mail Flow > Rules > Remove all Avanan Rules.
Remove Avanan Connectors.
admin.exchange.microsoft.com > Mail Flow > Connectors > Remove all Avanan Connectors.
Remove Avanan Groups.
admin.exchange.microsoft.com > Recipients > Groups > Remove all Avanan Groups.
Remove Avanan Journal Rule
https://purview.microsoft.com/datalifecyclemanagement/exchange/journalrules > Remove Avanan Rule.
All of these rules that are created during onboarding are detailed in the following guide for reference, we are simply verifying each has been removed to ensure smooth onboarding when you install again through the new account.
Manual Integration Guide: https://sc1.checkpoint.com/documents/Avanan_Admin_Guide/Topics-Harmony-Email-Collaboration-Admin-Guide/Appendix/Introduction_cp-manual-config-0365.htm#cp-manual-integration-o365
Step 3: Onboard with the New Check Point Account via Guardz
Proceed to install Check Point by following the instructions here:
Please Note:
This will provision a new Check Point tenant integrated through Guardz and will reinstall the SaaS application and all groups and rules connected with the Guardz provisioned tenant.
Google Workspace (GWS)
Step 1: Fully remove the current Check Point Email Protection Instance
Navigate to the Customer Portal for the tenant
Settings > SaaS Applications > Click ‘Stop’ on the mail SaaS application (and any others that are configured).
This will trigger Check Point to uninstall from the tenant.
Delete the tenant from the MSP Dashboard within Avanan (right click on the 3 dots to the far right of the tenant > delete).
Step 2: Validate Check Point has been Fully Removed
Usually, all components will be removed after completing the prior steps but it is recommend to verify manually before proceeding to the next step and reinstalling.
Confirm all rules created during the integration mentioned in the following article are removed: https://sc1.checkpoint.com/documents/Avanan_Admin_Guide/Topics-Harmony-Email-Collaboration-Admin-Guide/Appendix/Manual-onboarding-for-Gmail.htm?tocpath=Appendix%7C_____2
Verifying these rules have been removed will help ensure a smooth onboarding when you install again through the new account.
Step 3: Onboard with the New Check Point Email Protection Account via Guardz
Proceed to install Check Point by following the instructions here:
Please Note:
This will provision a new Check Point tenant integrated through Guardz and will reinstall the SaaS application and all groups and rules connected with the Guardz provisioned tenant.
