<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setup remote 2530 gateway to be managed centrally by Management Server in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/278327#M14003</link>
    <description>&lt;P&gt;Hello all.&lt;/P&gt;&lt;P&gt;I found the problem. As I have multiple WAN links and SD-WAN enabled, the 3920 was reciving the communication in WAN1, but was responding using WAN2. I fixed the route and it worked.&lt;/P&gt;&lt;P&gt;Thanks for all help.&lt;/P&gt;&lt;P&gt;Regads.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2026 13:16:51 GMT</pubDate>
    <dc:creator>RafaelBohrer</dc:creator>
    <dc:date>2026-06-11T13:16:51Z</dc:date>
    <item>
      <title>Setup remote 2530 gateway to be managed centrally by Management Server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/277875#M13966</link>
      <description>&lt;P&gt;Hello all.&lt;/P&gt;&lt;P&gt;I'm trying to setup a 2530 gateway in a remote site but it need be mananged by my central Management Server.&lt;/P&gt;&lt;P&gt;I've tried to use NAT all SIC ports directly to the SMS to connect the 2530 to my SMS. The trust is established, but I can`t fetch the policies.&lt;/P&gt;&lt;P&gt;How is the best practice to setup a remote gateway? I've read many saying to establish site-to-site VPN first.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I first configure 2530 in local mode, set the tunnel and then convert to central management?&lt;/P&gt;&lt;P&gt;Is there any document to help me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my topology.&lt;/P&gt;&lt;P&gt;Central Site:&lt;/P&gt;&lt;P&gt;1x 3920 Gateway with SD-WAN enabled. (Gaia 82.10 JHT19)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;3 external connections&lt;UL&gt;&lt;LI&gt;1 directly connect with public IP&lt;/LI&gt;&lt;LI&gt;2 behind a ISP modem with internal IP addresses&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;1x Management Server with 1 internal IP address (Smart Console 82.10)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remote Site&lt;/P&gt;&lt;P&gt;1x 2530 Gateway just with the initial setup done. (Gaia 82)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1 external connection behind ISP modem with DMZ configured to send to 2530 gateway IP&lt;/LI&gt;&lt;LI&gt;1 fixed public IP address&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Rafael Bohrer&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 13:21:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/277875#M13966</guid>
      <dc:creator>RafaelBohrer</dc:creator>
      <dc:date>2026-06-05T13:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: Setup remote 2530 gateway to be managed centrally by Management Server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/277890#M13967</link>
      <description>&lt;P&gt;You should consider "Management behind NAT", which also correctly populates the masters file on the remote gateway.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityManagement_AdminGuide/Content/Topics-SECMG/Security_Management_behind_NAT.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityManagement_AdminGuide/Content/Topics-SECMG/Security_Management_behind_NAT.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 16:59:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/277890#M13967</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-06-05T16:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Setup remote 2530 gateway to be managed centrally by Management Server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/277892#M13968</link>
      <description>&lt;P&gt;Thanks Alex. I`ll check it out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 17:26:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/277892#M13968</guid>
      <dc:creator>RafaelBohrer</dc:creator>
      <dc:date>2026-06-05T17:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Setup remote 2530 gateway to be managed centrally by Management Server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/278029#M13969</link>
      <description>&lt;P&gt;Hello Alex.&lt;/P&gt;&lt;P&gt;I've followed the steps from the documentation. The 2530 established the communication, but still dot fetching the policies.&lt;/P&gt;&lt;P&gt;Here's the error message on 2530 WebGui&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de Tela 2026-06-08 às 11.13.13.png" style="width: 503px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34425i35A8716099C7AA12/image-dimensions/503x105?v=v2" width="503" height="105" role="button" title="Captura de Tela 2026-06-08 às 11.13.13.png" alt="Captura de Tela 2026-06-08 às 11.13.13.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; Any thing that&amp;nbsp; I'm missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 14:14:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/278029#M13969</guid>
      <dc:creator>RafaelBohrer</dc:creator>
      <dc:date>2026-06-08T14:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Setup remote 2530 gateway to be managed centrally by Management Server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/278030#M13970</link>
      <description>&lt;P&gt;You can reset the SIC on the SMS and set it to wait for first contact, then install the policy on your gateway object. Check the first option on the install screen, "install independently..." and uncheck the "if it fails on one gateway..." then proceed.&lt;/P&gt;
&lt;P&gt;From the WebUI of the Spark, reinitialize SIC with the password you set in the manager.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 14:25:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/278030#M13970</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-06-08T14:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Setup remote 2530 gateway to be managed centrally by Management Server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/278071#M13971</link>
      <description>&lt;P&gt;Still not working, but now this message on Test SIC Connection in SmartConsole&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;SIC Status for SC-CPFW-01: Unknown&lt;/P&gt;&lt;P&gt;Could not establish TCP connection with 179.219.xxx.xxx&lt;/P&gt;&lt;P&gt;** Please make sure that Check Point Services are running on SC-CPFW-01 and that TCP connectivity is allowed from Security Management Server to IP 179.219.xxx.xxx, Port 18191 **&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 19:20:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/278071#M13971</guid>
      <dc:creator>RafaelBohrer</dc:creator>
      <dc:date>2026-06-08T19:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Setup remote 2530 gateway to be managed centrally by Management Server</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/278327#M14003</link>
      <description>&lt;P&gt;Hello all.&lt;/P&gt;&lt;P&gt;I found the problem. As I have multiple WAN links and SD-WAN enabled, the 3920 was reciving the communication in WAN1, but was responding using WAN2. I fixed the route and it worked.&lt;/P&gt;&lt;P&gt;Thanks for all help.&lt;/P&gt;&lt;P&gt;Regads.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 13:16:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Setup-remote-2530-gateway-to-be-managed-centrally-by-Management/m-p/278327#M14003</guid>
      <dc:creator>RafaelBohrer</dc:creator>
      <dc:date>2026-06-11T13:16:51Z</dc:date>
    </item>
  </channel>
</rss>

