- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
we have Quantum Spark 1900 Appliance [R81.10.15] and we need to add it to a management Server [R81.20], which located in another country und runs on a VM. The connection will go through Internet.
The first question: what is the best way to do this? I heard, if I add an Appliance, no existing rules will be copied to the Management server, as well as VPN connections. If it is true, how can I export them and import into the Management Server?
The second question: in Appliance we can set up the sending of logs to the Management Server, but the configuration requires "SIC one-time Password". If I set up sending logs, won't the log server also become a management server, and then I'll lose everything again (since the rules won't be copied)?
Thank you!
In the past if you wanted to have your logs from a locally managed SMB appliance visible in the central management then there was a process for this documented here: sk108437 - How to configure the External Security Log Server on Locally Managed SMB appliances I've not tested this on recent versions however.
Central management requires SIC, in order to go from local to central appliance will be reset.
It should show this in the wizard. Rules you have to make manually in new management.
maybe this video helps, bit older but still shows the trick
Here you can see difference between local and mgmt:
https://support.checkpoint.com/results/sk/sk178604
I see... and since the process of switching to central management is not fast, I need a temporary solution for collecting logs, and therefore I have a third question. I have configured the appliance to send syslog to the "management server", I see that traffic is coming - but how can I view the logs themselves in the console? In particular, I'm interested in VPN connection logs, but I don't see anything in the standard logs console...
Thank you!
If it is raw syslog did you already enable "accept syslog messages" on the Management object and install database or some other approach?
yes, i did
In the past if you wanted to have your logs from a locally managed SMB appliance visible in the central management then there was a process for this documented here: sk108437 - How to configure the External Security Log Server on Locally Managed SMB appliances I've not tested this on recent versions however.
thank you it did help. Unfortunatelly the article doesn't explain the Ports to be open:
srs: mgmt/log server
dst: firewall
ports: 18191, 18192, 18211
srs: firewall
dst: mgmt/log server
ports: 18191, 257, 18210
Last question: how fast will the logs appear on the log server?
I forgot to install database - everything works prefect, thanks a lot!
1st Q: You can not export any rules from local management, so this has to be set up freshly
2nd Q: These are two different things: You can just use the SMS as a log server or let it do both central management and log server. SIC is alwqays needed
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 13 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY