Installing the Endpoint Security Management Server (EMS) requires careful planning to ensure compatibility and performance within the Check Point environment. TheCheck Point Harmony Endpoint Server Administration Guide R81.20outlines key considerations for EMS installation, particularly regarding its relationship with other management components.
Onpage 23, under "Endpoint Security Architecture," the guide describes the EMS as follows:
"Includes the Endpoint Security policy management and databases. It communicates with endpoint clients to update their components, policies, and protection data."
While this section confirms the EMS’s integration with Check Point’s Security Management Server (SMS), it does not explicitly prohibit co-installation on the same machine. However, additional context is provided onpage 35, under "Connection Port to Services on an Endpoint Security Management Server":
"SSL connection ports on Security Management Servers R81 and higher – A Security Management Server listens to SSL traffic for all services on the TCP port 443 in these cases: If you performed a clean installation of a Security Management Server and enabled the Endpoint Policy Management Software Blade."
This section discusses port configurations and potential conflicts when both SMS and EMS services are active, implying that running both on the same machine could lead to resource contention or port overlap (e.g., TCP/443 vs. TCP/4434). Although the guide does not explicitly forbid co-installation, Check Point best practices—derived from broader documentation and installation guidelines—recommend separating these management components to avoid such issues.
Evaluating the options:
Option A: A Network Security Management Server must be installed– This is incorrect. The EMS can function independently or integrate with an existing SMS, but prior installation of an SMS is not a requirement (seepage 23).
Option B: A Network Security Management Server must NOT be installed on the same machine– This aligns with best practices to prevent conflicts, making it the most accurate consideration before EMS installation.
Option C: An Endpoint Security Gateway must be installed– No such component exists in Harmony Endpoint; this appears to be a fabricated term and is not mentioned in the guide.
Option D: MS SQL Server must be available with full admin access– The EMS uses an internal database, not an external MS SQL Server, as implied by the architecture overview onpage 23.
Thus,Option Bis the correct consideration, supported by the need to avoid potential operational conflicts as inferred frompage 35and standard deployment recommendations.
[References:, CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 23: "Endpoint Security Architecture" (EMS components)., CP_R81.20_Harmony_Endpoint_Server_AdminGuide.pdf, Page 35: "Connection Port to Services on an Endpoint Security Management Server" (port considerations)., ]