- Products
- Learn
- Local User Groups
- Partners
- More
What's New in Check Point SASE
Wednesday, 9 September @ 5pm CET / 11am EDT
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
We have an on-prem SMS that currently manages a couple of on-prem firewalls. We are deploying a Checkpoint cluster in Azure and need to manage it from our on-prem SMS. How do we accomplish this?
SIC is an encrypted protocol. You need to make sure you have an automatic public NAT address for your SMS with the "use for control connections" enabled, and then connect to the public (Azure NAT) IPs. This is perfectly safe and is used by thousands of customers with no issue today.
Adding the Azure gateways to your on-prem SMS works the same as it does for your on-prem gateways: establish SIC and install policy.
Setting the cluster up in Azure to get to that point, on the other hand…https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Clust...
Additional info. We do not have a communication path to Azure from our SMS. Do we need to have a VPN or other direct communication path to Azure in order for the SMS to communicate with the newly deployed Checkpoint cluster? Or is there a mechanism within the SMS to connect to Azure directly?
I recall seeing some sort of plug in (if thats the right word) you can run on sms for this, just cant remember the process now. Let me see if I can find it for you.
Thanks Andy. Seems to be a Catch22. On-prem SMS and Azure Checkpoint. If I dont have a path to Azure from my network where the SMS resides, how can I add the new firewall and apply policy.
Hm...thats bit tricky situation, exactly sounds like catch 22, as you said. There would need to be some way for sms to communicate with Azure gw. Are you able to ping public azure IP from sms itself at all?
Not sure if what I said before would apply, I am sure I was thinking of a specific script in $FWDIR/scripts dir, but if its on prem mgmt, doubt it would be there by default. If you send a content of that dir, I can easily confirm.
A network connection is required to initialize SIC, install policy, and send logs back to the management/log server.
Ok. So how are customers who have on-prem SMS and are building Checkpoint firewalls in Azure making this solution work? VPN?
I know people who did this without any issues. Im no Azure expert by any means, but I believe you may need to look at some sone policies in azure portal, also proper routing needs to be in place.
The gateways are exposed to the Internet through your Azure configuration.
Hi PB. So we would use the front end IPs (Azure NATs) as the VPN termination AND for management of the Azure checkpoint cluster? Isn't that a security risk?
SIC is an encrypted protocol. You need to make sure you have an automatic public NAT address for your SMS with the "use for control connections" enabled, and then connect to the public (Azure NAT) IPs. This is perfectly safe and is used by thousands of customers with no issue today.
That makes perfect sense.
Yes, that's how you do it.
All SIC traffic is authenticated and encrypted.
The default firewall policy blocks unnecessary traffic.
It's no different than managing a remote physical gateway over the Internet, something customers have been doing for decades.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 6 | |
| 6 | |
| 6 | |
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY