- Products
- Learn
- Local User Groups
- Partners
- More
Check Point
for Beginners
OPEN OTHER ARTICLES
The Security Management Portal (SMP), with its intuitive web-based user interface, enables managed service providers to provision security efficiently for small businesses. With a robust architecture that scales to manage up to 10,000 Check Point Small Business appliances, the SMP easily keeps pace with your security-as-a-service business.
This document is
The SMP includes an Administration Guide. Context sensitive on-line help is available in the Web User Interface.
No one understands security better than Check Point. That is why the Check Point Security Management Portal can provide unparalleled protection for your network assets. The service has a highly scalable and configurable structure – whether you have a single location with a few employees or multiple locations with hundreds of employees, you are covered. The Check Point Cloud Hosted Security Management Portal (SMP) is a fully-hosted, large scale central management and service (SaaS) provisioning platform.
The Security Management Portal leverage enterprise-grade protection for small to medium businesses and comes for free with one 1500 series Appliance. Check Point offers you to ability to manage more than one 1500 series Appliance with SMP extensions starting at $1,030 for 10 Appliances.
More information is available at https://www.checkpoint.com/products/security-management-portal/.
Check Point offers several unique, sophisticated cloud services for management of the SMB gateways.
The Security Management Portal simplifies the deployment and maintenance of Check Point SMB gateways using group-based management tools. Administrators define multiple service plans, each consisting of a template that defines the plan’s expiration date, gateway properties, VPN settings, as well as additional services such as Anti-Virus protection and content filtering. Plans can be associated with an unlimited number of SMB gateways which inherit all of that plan’s properties. Specific aspects can be overridden if required. When the administrator updates the plan, the changes are automatically applied to all associated gateways.
The cloud-managed service, Security Management Portal, SMP you can manage the security policy, firmware upgrades (gradual and remote scheduled), Cyber Views and periodic backups. Key benefits of the SMP:
Below is a screenshot that shows the customer view and the features.
For Internet Service Providers (ISPs) and Managed Service Providers (MSPs) the cloud-managed service offers an interface to manage and support thousands of their customers easily and intuitively. This includes security policy management, firmware upgrades, automatic backups, periodic reports and VPN community support which is essential when using these appliances in the retail sector. Key benefits of the service to ISPs and MSPs are;
A demo site of the cloud managed interface is available. Ask your Check Point contact to provide access to the demo. Highlights of the interface are shown below for your convenience.
Create a template. Template -> New -> Small Office Gateway
Note | If you are using ADSL/VDSL you need to configure the PPPoE settings first. For this we offer One Touch. You can addd the PPPoE configuration to USB stick and and let the gateway boot from the USB stick. This will start the autoconf.clish
Guide |
Link |
---|---|
Zero Touch Administration |
|
Zero Touch API |
Check Point PRO Support is a proactive, protective and a professional service. Check Point PRO Support combines security expertise and machine intelligence to monitor your security gateways daily and identify points of failure before they occur. When a severe issue is detected, a Check Point PRO expert proactively contacts you to help resolve the issue and prevent service downtime. Check Point PRO also provides you with a comprehensive report, delivering an overview of your overall security, diagnostics and actionable insights.
More information at sk121072
Check Point Reach My Device, RMD is service for customers allowing access to SMB gateways which are situated behind a NAT device, i.e. router. RMD provides a shell and WebUI access.
Under the Service Domain Settings you can set the configuration that holds domain specific configurations. Configure the domain to meet your requirements. You can configure your Time Zone, a Syslog Server, DNS settings, Mail Settings, Firmware, X.509 Certificates, Notifications, Alerts, Two step authentication, API access and RADIUS authentication.
Configure API Access if you wish integrate.
You might want to configure RADIUS authentication for centralized Authentication, Authorization, and Accounting.
The SMP serves 3 activation methods for connecting the security gateway to the SMP.
Copy the activation key into your 1500 Appliances.
The 1500 Appliances will contact the SMP and fetch the configuration in 3 steps.
Notice: if enrolment fails, check and enable if needed RMD, Reach My Device.
Under the devices settings you can define the NTP servers, DNS servers and gateway administrators. All gateways assigned to this plan will inherit these settings. Notice the NTP security.
We offer the feature to block other undesired applications from the predefined list.
With the SMP you manage exceptions and bypass rules, define what SSL logs needs to generated and bypass policies. With CLI you add custom bypass rules.
For the 1500 series Appliance we are supporting the Unified Threat Prevention. The policy is applicable for Anti-Virus, Anti-Bot, IPS and Threat Emulation.
To automate specific configuration settings the SMP support CLI scripts. In this example we will enable SafeSearch. This configuration setting is normally done locally on the 1500 Appliance itself. However via CLI scripting we push this configuration to 1500 appliance managed by the SMP.
set application-control-engine-settings advanced-settings enforce-safe-search true
With the SOC like feature Cyber Views you can track security incidents, infected hosts, follow attack trends with time line and much more. It will give a clear overview of the current state of your network with a single overview. Cyber Views is embedded in the SMP. And a great tool for a SOC. It will inform you about:
All information is clickable and allows you to jump to the event or detailed log information.
Below an example of infected hosts with the SMP domain.
Or track the detected attacks.
The SMP offers extensive and tailored, scheduled reporting. Report on a regular base to your customers with a dedicated customized report.
The SMP can provide a report of the Service Domain itself. Providing valuable insight on your domain with:
Click on Overview -> Generate Report
See the difference between reports from the gateway and plan. You can create a fully customized report for your customer with own logo.
Below report will appear. Informing you how many were scanned, emulated and found malicious.
The SMP gateway logs will allow to investigate events occurring on your network. The SMP offers Gateway Logs, System Logs and Activity Logs. You can easily look for source, source port, destination, interface, blade and much more.
Jump to the log card for detailed information of the event by clicking on the event.
Receive email notifications of your SMP domain. The email notifications will alert you about Security Incidents, Networking Events and Operational Events.
Click on Home -> Plans -> Your plan -> Services -> Notifications. And notice the available options.
Click on Notification Recipients to configure who will receive those alerts.
Beside the notifications you can also configure custom alerts that meets your requirement.
Check Point recommends to regular backup your environment. Click on Home -> Plans -> Services -> Periodic Backup. Notice the schedule. To automate this process you might want to consider a CLI script performing this task.
Example: backup settings to tftp server <serverIP> <filename>] [file-encryption {off|on password <pass>}] [backup-policy {on|off}] [add-comment <comment>]
The SMP offers several options to upgrade your environment. This will make your life as administrator so much easier. The following options are available:
Notice that you need to set a schedule for the upgrade service.
Click on Plans -> Select your plan -> Services -> Firmware.
New users with different permissions (based on their defined role) can easily be added to the SMP.
The Zero Touch Portal supports the use of API’s to automate initial deployments. The Zero Touch Cloud Service allows users to easily manage the initial deployment of their Small and Medium Business SMB gateways.
More information is available at
sk116136 Orchestrated Rollout of LSM Centrally Managed 1100/1200R/1400 SMB Appliances - Demo Kit
sk116375 Zero Touch Cloud Service for Gaia OS and Gaia Embedded SMB appliances
The Security Management Portal (SMP), with its intuitive web-based user interface, enables managed service providers to provision security efficiently for small businesses. With a robust architecture that scales to manage up to 10,000 Check Point Small Business appliances, the SMP easily keeps pace with your security-as-a-service business.
This document is
The SMP includes an Administration Guide. Context sensitive on-line help is available in the Web User Interface.
No one understands security better than Check Point. That is why the Check Point Security Management Portal can provide unparalleled protection for your network assets. The service has a highly scalable and configurable structure – whether you have a single location with a few em
...You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY