- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
As per my understanding, checkpoint appliance can be installed with Gateway & SMS as a bundle or separately. Hence, is there anyway that I could know the deployment method of the security appliance?
I'm taking over checkpoint appliance with limited info onhand, how should I identify above?
Thanks
Expert@MGMT:0]# fwm ver
This is Check Point Security Management Server R81 - Build 11
[Expert@MGMT:0]#
- Also check the Management IP you login to
- Check the licensing, you may have central licensing.
- Expert@MGMT:0]# cpprod_util CPPROD_GetInstalledProducts
- cpprod_util FwIsFirewallMgmt (If it returns a 1 then the device is the manager
[Expert@MGMT:0]# cpprod_util FwIsStandAlone (If it returns 0 then this is just a gateway)
Hi,
Thank you very much for your info. I have ran the command above in my staging VM and it shows what I need.
[Expert@gw-cp-ASUS:0]# cpprod_util FwIsFirewallMgmt
1
[Expert@gw-cp-ASUS:0]# cpprod_util FwIsStandAlone
1
Should the existing appliance comes along with both GW+Security Management installation, would it be possible if I manage from the SMS? having to say, I'm having a plan to reorganize the firewalls under 1 hood. As in current setup, some firewalls are managed via SMS, some are not, which lead me to the doubt why they are not managed under 1 hood.
Thanks
That is the good approach to centrally manage under one hood, as you have logs and events from all GWs:
- check the current central SMS license for number of GWs and SmartEvent 8)
- for the StandAlone GWs i would do a fresh install of current version and apply central management
Hi,
Thanks for your kind input. I will definitely check on it. I guess I know the reason now why gateways weren't managed under SMS previously which could due to licensing issue.
Meanwhile, should I conclude that standalone GW is not manageable from SMS, in which fresh installation with GW installation only needed in this scenario?
Thank you
Yes, there is a different number of GWs included in the SMS license, that could be the reason for StandAlone deployment. A StandAlone GW can be turned to central management without, but fresh install is my advice.
Look into Checkpoint Usercenter - customers account. You will find the ordered appliance blades listed. CP Gateway appliances mostly include a SMS license.
Go to Product Center and select the device (4607 is the example used here):
On double-click, you will see the licenses:
You see here CPSB-NPM / LOGS -For-GW, so we have a included SMS license here.
This is bound to the hardware, so the best SMS solution (VM) would need an additional license (including SmartEvent, a clear muss for security).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY