- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Security Management and Gateway Same Host?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Security Management and Gateway Same Host?
Hi All,
Has anyone ever installed the Security management server and Gateway on the same Host when doing the initial first time build?
I have a client where they don't have a server to install the Management Server on so initially want to build it on the same Gai boxes (6600's).
My main concern would be if you setup Cluster XL or VRRP for the Gateways how would it differentiate between the 2? I haven't set this up before in this way,but would like to hear any gotchas and experiences you may have?
Thanks in advance.
Alan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do not do it 8) ! The most dreaded installation is the Fool Management HA Cluster 😉. Better use SMS in the Cloud if there is no hardware for a VM.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for your quick for your response, appreciated :-)! Have you used SMS in the cloud for Checkpoint management? any pointers much appreciated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Easy to try yourself - see https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/T.... You can evaluate Smart-1 Cloud there as well as others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you sir! How does this communicate with on premise Gair devices btw? obviously Internet access would need to be allowed but I'm not sure if that's possible initially.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Smart-1 Cloud only requires the gateway to have internet access. (https)
The gateway will establish a secure vpn tunnel to the smart-1 cloud service and run all management services in the tunnel. (No more need to worry about all the 1819x ports, and no inbound access required, so it even works behind NAT environments.)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Sigbjorn, So you have to do something different on the gateway if its on prem? I'm just interested on how it establishes its VPN tunnel to the smart-1 cloud, I just normally set everything up using cpconfig for the SIC etc. Are the Gateways running different versions of software to be Smart-1 enabled?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gateways just have to be running R80.10+.
We did a TechTalk on Smart-1 Cloud, see: https://community.checkpoint.com/t5/Smart-1-Cloud/Moving-Security-Management-to-the-Cloud-Video-Slid...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Greetings,
Before making the jump to the Smart-1 Cloud, make sure you take into account any other apps/feeds provided by an on-prem SMS/MDS. What I mean is do you have Splunk or Netskope or something similar that takes log info from the SMS/MDS? If you do, your app may not be supported yet from a Cloud SMS/MDS. If you don't have any dependencies like this, you're good to go.
Regards,
Luis
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Luis,
I was thinking about this and one of the main points would be where would the Gateways forward their logs to? by default the Management Server which is where in the cloud? or could you maybe forward logs to a different checkpoint Log Server.
Cheers
Alan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Alan,
We have an on-prem MDS, so we forward logs to our on-prem Netskope server. We do the same thing for Splunk with the same architecture as Netskope. If you have a similar need, but your SMS/MDS is in the Cloud, I think the solution is to use Log Exporter with the TLS capability at sk122323 . Log Exporter is easy to set up though I don't use the SMS/MDS in the Cloud.
Regards,
Luis
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By default, gateways forward their logs to the management server unless differently configured.
In the case of Smart-1 Cloud, that means being forwarded to the cloud.
