Skip to main content

Check Point Email Protection (Avanan) – Bring Your Own

Overview:

Bring Your Own (BYO) lets MSPs and customers who already hold a Check Point Email Protection (formerly Avanan) license connect that existing license to Guardz, instead of purchasing the service through Guardz.

The customer continues to pay Check Point directly — Guardz does not bill for the service — while supported email security issues are synced into the Guardz platform, so detections can be viewed and remediated from one place.

How it works

  • The customer keeps their existing Check Point (Avanan) license and account; billing stays directly with Check Point.

  • Guardz connects to that account and syncs only Guardz-supported event types into the platform.

  • Detections appear as in Guardz, where the supported investigation and remediation actions are available.

  • All settings and policy configurations are managed exclusively through the Check Point (Avanan) console. Guardz platform does not support viewing or modifying these configurations.


BYO Feature Support Details:

Supported in Guardz

Managed in Check Point (Avanan) Console

Issue Type

• Quarantine Emails

• Spam Emails

• Alert Emails

All others (Shadow IT, Anomaly, etc.)

Issue Investigation

• Threat

• DLP Verdict

• DLP Detections

• Subject

• From / To / CC

• Authentication results: SPF check

• Remediation action details

• Mailboxes

• Show email preview

• Show email header

• Phishing Category

• Authentication results:

  1. DKIM

  2. DMARC

Issue Remediation

• Quarantine Email

• Restore Email

• Move to Spam

• Dismiss Issue

• Mark as Safe

Exceptions

• Anti-Phishing:

  1. Email

  2. Domain

  3. IP

• Anti-Spam

• Anti-Phishing: Header

• Click-Time Protection

• Anti-Malware

• Data Loss Prevention


Setting-up the BYO Service

To connect an existing license, the customer authorizes Guardz to read from their Check Point account, typically by providing a key/token generated by Check Point.

Below are step by step guidelines:

  1. Select the all customers view

  2. Go to Security Controls page and scroll down to the Email Protection section

  3. Click the 'Connect Account' button

  4. Fill in the following details:

    • Application ID

    • API Secret

    • Data Center (currently, the integration supports a single Check Point data center only)

      Note:

      These values must be obtained from Check Point Support, so admins may will need to contact their support team to request them.

  5. Click the 'Test Account' button

    If the connection is established successfully, you'll see the number of active Check Point tenants associated with the MSP displayed on the screen.

  6. Click the 'Connect Account' button

    1. Connect and map each Check Point (Avanan) tenant to the corresponding Guardz tenant.

    1. Review the suggested mappings. Automatic suggestions are provided, but they should be verified before proceeding.

    2. Confirm each tenant mapping to complete the connection.

    3. Whenever new tenants are added in Check Point (Avanan), click Refresh Suggestions to refresh the automatic mapping and ensure the new tenants are included.

  7. After a successful integration, the following two areas of the platform indicate the integration status:

    1. Tenant level:

      A new Check Point section is displayed under Email Security.

    2. Global view:

      The tenant record is marked with BYO and a green check mark to indicate a successful connection.


Available Actions for Active Customers

The following management actions are available already BYO onboarded customers:

  • Disconnect:

    Disables the integration between Check Point and Guardz. The integration status changes to Deactivated, while the tenant continues to be protected by Check Point.

  • Edit Credentials:

    Update the integration credentials if required. New credentials must be obtained from Check Point Support. Updating the credentials may require disconnecting and recreating the existing tenant mappings. If so, re-establish the mappings after the new credentials have been applied.


BYO Detection Limitations

BYO detections have the following behavior:

  • They are not included in the Digest reports.

  • They are not visible in the End User Portal.

  • They generate issue notifications only in Guardz, according to the configured notification policies.


BYO Remediation for Detected Issues:

  • Detection details for BYO integrations are more limited than those available for full Guardz-managed deployments.

  • The relevant remediation actions are presented for each issue, based on the supported capabilities.

  • If Restore Email is selected, the customer can choose to add the email address or domain to the Allow List or Block List. These changes are synchronized with the corresponding exceptions in the Check Point (Avanan) portal.

  • Any remediation performed through the Guardz platform is also reflected in the Check Point portal.

  • Likewise, if an issue is remediated directly in the Check Point portal, the remediation status and related details are synchronized back to Guardz and displayed in the platform.

Did this answer your question?