- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: Where can I obtain a SIC to access my CloudGua...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Where can I obtain a SIC to access my CloudGuard on AWS?
Hello,
I have deployed a "CloudGuard Network Security Next-Gen Firewall with Threat Prevention" instance in my AWS cloud account.
I have connected to it via https:// and logged in to the instance.
I am redirected to some initial setup window that requires that I enter something called SIC activation key.
I wanted to know where can I obtain this from in order to proceed with my deployment.
Thanks in advance,
Daniel
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can enter anything there, min 4 characters. SIC will be needed as one time key to establish communition between mgmt and firewall. Its encrypted and not saved anywhere.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need to create one on your management server. Please follow the deployment guide for your installation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can enter anything there, min 4 characters. SIC will be needed as one time key to establish communition between mgmt and firewall. Its encrypted and not saved anywhere.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks this has resolved my issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Glad we can help. Just remember this, though most people are aware, but there might be some that are not. IF you reset SIC on the gateway via cpconfig menu, it will load initial policy, which would pretty much block anything, except ssh and web UI (if on port 443, any other port would be blocked), until you apply the actual policy from the mgmt server, after you establish SIC again.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi the_rock,
Thanks for the information.
Is there any reason for me to change this SIC via cpconfig menu? Is it not recommended to keep the same SIC in the long term?
Thanks in advance,
Daniel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not really...the ONLY reason would be if sic was broken (you could see that from the object in smart console, it would give an error probably during policy push), but that only happens if communication with mgmt was broken.
Put it this way, if policy works, no need to touch sic. As I mentioned, sic key is one time key thats encrypted and not saved anywhere, simply needed for mgmt <-> fw communication on port 18209
SIC key can be anything...1234,abcd, planetearth, homersimpson, adamsfamily...you get an idea, makes no difference. As you did yesterday, you type same thing on gateway, then in smart console for the object representing fw, push policy, done, NO need to touch SIC ever again unless communication broke.
Makes sense?
Best,
Andy