- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: SMB Questions (management & fetching policy)
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SMB Questions (management & fetching policy)
Hello CheckMates;
We have some questions regarding the SMB platform.
We were under the impression that these device could call home ang grad policy from centrally managed check point. We are testing this in our lab with R77.20 and 1200R R7720.81
Looking at /var/log/log/sfwd.elg we see it calling out but then saying "Local security policy is up to date" "same policy as already on module"
We are also considering deploying these in our SCADA environment in the field over very slow links and were hoping the policy install would be a quicker process compared to a regular gateway running full Gaia. Not sure this would be a smaller file resulting in a faster (lass bandwidth intensive) policy install.
And our other question is whats the differences between using Smart Provisioning (LSM) or the newer product SMP? Are there any advantages? One thing We would need in our environment is to keep all management local on Prem as opposed to being in the cloud. We are told this due to NERC-CIP guidelines.
Thanks and appreciate any direction / experience anyone can share.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
(Yes, this mentions an 1100, but the process should be similar)
You may want to engage with the TAC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SmartLSM creates a “profile” that represents many different gateways, not necessarily SMB gateways.
When you push policy to a SmartLSM gateway, it doesn’t actually push the policy to the gateway but creates a new policy for the gateway to fetch, which they will then do periodically.
SmartLSM has a few limitations in terms of features/blades supported, so it may not be appropriate in every situation.
Current SMB appliances don’t necessarily need SmartLSM insofar as they periodically fetch policy from management already.
The compiled policy isn’t necessarily smaller if you use SmartLSM.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
(Yes, this mentions an 1100, but the process should be similar)
You may want to engage with the TAC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
