Hi Check Point Community,
I would appreciate your advice on the following deployment scenario and whether it aligns with Check Point best practices.
Proposed Production Architecture
Site A (Headquarters)
Site B (Remote Branch)
Implementation Challenge
During the initial deployment, there will be no WAN/MPLS connectivity between Site A and Site B. As a result, the Quantum 2000 at Site B cannot initially communicate with the Smart-1 700S located at Site A.
To overcome this, I am considering the following implementation approach:
Deploy a temporary Security Management Server (SMS) as a virtual machine at Site B.
Establish SIC with the Quantum 2000 gateway.
Configure network objects, security policies, NAT, VPNs, and complete implementation and acceptance testing.
Once the WAN/MPLS connection between Site A and Site B is established, deploy the production Smart-1 700S at Site A
Migrate the complete management database from the temporary SMS VM to the Smart-1 700S using the Check Point Migration Tools.
Manage both the Quantum Force 9300 at Site A and the Quantum 2000 at Site B from the centralized Smart-1 700S.
Questions
Is this implementation and migration approach fully supported by Check Point?
Can the gateway's SIC trust be preserved after migrating the management database to the Smart-1 700S, or will SIC need to be re-established?
Are there any licensing considerations when using a temporary SMS VM for staging before migrating to the production Smart-1 appliance?
Would you recommend this approach, or is there a better practice for implementing a remote gateway before WAN connectivity to the central management server becomes available?
The objective is to avoid deploying a permanent Smart-1 appliance at the remote site while still completing implementation, testing, and commissioning before the WAN connection to the headquarters is established.
I appreciate any recommendations or best practices from those who have implemented a similar scenario.