Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CheckPointerXL
Advisor
Advisor

Avoid Initial Policy - "Zero Touch" Deployment

Hi all,

sometimes it happens that we need to configure FWs and then sent to Datacenter/branch offices.

At startup FWs load Initial Policy, so we cannot connect from MPLS or Internet. Every time console access is needed to perform fw unloadlocal.

Any workaround?

0 Kudos
4 Replies
Lloyd_Braun
Collaborator

You can customize the default filter policy:

 

Boot Security (checkpoint.com)

0 Kudos
D_W
Advisor

Good to know that this is also possible. 👍

0 Kudos
D_W
Advisor

We always prepare the GWs in our HQ before sending them out to the Sites. Including all Gaia Settings, established SIC and correct policy installed. Last thing before shipping is to change the WAN IP and default Route in Gaia and change the Main IP also in the Management. Only thing to do When it gets connected at the Site is to install the policy again to „activate“ the new WAN IP.

0 Kudos
PhoneBoy
Admin
Admin

You realize we have a Zero Touch service that can assist with this:? https://sc1.checkpoint.com/documents/SMB_R80.20.15/AdminGuides/Locally_Managed/EN/Topics/Zero-Touch-... 
See also: https://welcome.checkpoint.com (production) or https://welcome-stg.checkpoint.com (Staging) which offers another mechanism to onboard appliances.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events