- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
We have an on-prem SMS that currently manages a couple of on-prem firewalls. We are deploying a Checkpoint cluster in Azure and need to manage it from our on-prem SMS. How do we accomplish this?
SIC is an encrypted protocol. You need to make sure you have an automatic public NAT address for your SMS with the "use for control connections" enabled, and then connect to the public (Azure NAT) IPs. This is perfectly safe and is used by thousands of customers with no issue today.
Adding the Azure gateways to your on-prem SMS works the same as it does for your on-prem gateways: establish SIC and install policy.
Setting the cluster up in Azure to get to that point, on the other hand…https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Clust...
Additional info. We do not have a communication path to Azure from our SMS. Do we need to have a VPN or other direct communication path to Azure in order for the SMS to communicate with the newly deployed Checkpoint cluster? Or is there a mechanism within the SMS to connect to Azure directly?
I recall seeing some sort of plug in (if thats the right word) you can run on sms for this, just cant remember the process now. Let me see if I can find it for you.
Thanks Andy. Seems to be a Catch22. On-prem SMS and Azure Checkpoint. If I dont have a path to Azure from my network where the SMS resides, how can I add the new firewall and apply policy.
Hm...thats bit tricky situation, exactly sounds like catch 22, as you said. There would need to be some way for sms to communicate with Azure gw. Are you able to ping public azure IP from sms itself at all?
Not sure if what I said before would apply, I am sure I was thinking of a specific script in $FWDIR/scripts dir, but if its on prem mgmt, doubt it would be there by default. If you send a content of that dir, I can easily confirm.
A network connection is required to initialize SIC, install policy, and send logs back to the management/log server.
Ok. So how are customers who have on-prem SMS and are building Checkpoint firewalls in Azure making this solution work? VPN?
I know people who did this without any issues. Im no Azure expert by any means, but I believe you may need to look at some sone policies in azure portal, also proper routing needs to be in place.
The gateways are exposed to the Internet through your Azure configuration.
Hi PB. So we would use the front end IPs (Azure NATs) as the VPN termination AND for management of the Azure checkpoint cluster? Isn't that a security risk?
SIC is an encrypted protocol. You need to make sure you have an automatic public NAT address for your SMS with the "use for control connections" enabled, and then connect to the public (Azure NAT) IPs. This is perfectly safe and is used by thousands of customers with no issue today.
That makes perfect sense.
Yes, that's how you do it.
All SIC traffic is authenticated and encrypted.
The default firewall policy blocks unnecessary traffic.
It's no different than managing a remote physical gateway over the Internet, something customers have been doing for decades.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 36 | |
| 11 | |
| 10 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 6 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY