- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi All,
Has anyone ever installed the Security management server and Gateway on the same Host when doing the initial first time build?
I have a client where they don't have a server to install the Management Server on so initially want to build it on the same Gai boxes (6600's).
My main concern would be if you setup Cluster XL or VRRP for the Gateways how would it differentiate between the 2? I haven't set this up before in this way,but would like to hear any gotchas and experiences you may have?
Thanks in advance.
Alan
Do not do it 8) ! The most dreaded installation is the Fool Management HA Cluster 😉. Better use SMS in the Cloud if there is no hardware for a VM.
Thanks for your quick for your response, appreciated :-)! Have you used SMS in the cloud for Checkpoint management? any pointers much appreciated.
Easy to try yourself - see https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/T.... You can evaluate Smart-1 Cloud there as well as others.
Thank you sir! How does this communicate with on premise Gair devices btw? obviously Internet access would need to be allowed but I'm not sure if that's possible initially.
Smart-1 Cloud only requires the gateway to have internet access. (https)
The gateway will establish a secure vpn tunnel to the smart-1 cloud service and run all management services in the tunnel. (No more need to worry about all the 1819x ports, and no inbound access required, so it even works behind NAT environments.)
Thanks Sigbjorn, So you have to do something different on the gateway if its on prem? I'm just interested on how it establishes its VPN tunnel to the smart-1 cloud, I just normally set everything up using cpconfig for the SIC etc. Are the Gateways running different versions of software to be Smart-1 enabled?
Gateways just have to be running R80.10+.
We did a TechTalk on Smart-1 Cloud, see: https://community.checkpoint.com/t5/Smart-1-Cloud/Moving-Security-Management-to-the-Cloud-Video-Slid...
Thank you
Greetings,
Before making the jump to the Smart-1 Cloud, make sure you take into account any other apps/feeds provided by an on-prem SMS/MDS. What I mean is do you have Splunk or Netskope or something similar that takes log info from the SMS/MDS? If you do, your app may not be supported yet from a Cloud SMS/MDS. If you don't have any dependencies like this, you're good to go.
Regards,
Luis
Thanks Luis,
I was thinking about this and one of the main points would be where would the Gateways forward their logs to? by default the Management Server which is where in the cloud? or could you maybe forward logs to a different checkpoint Log Server.
Cheers
Alan
Hi Alan,
We have an on-prem MDS, so we forward logs to our on-prem Netskope server. We do the same thing for Splunk with the same architecture as Netskope. If you have a similar need, but your SMS/MDS is in the Cloud, I think the solution is to use Log Exporter with the TLS capability at sk122323 . Log Exporter is easy to set up though I don't use the SMS/MDS in the Cloud.
Regards,
Luis
By default, gateways forward their logs to the management server unless differently configured.
In the case of Smart-1 Cloud, that means being forwarded to the cloud.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 3 |
Tue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY