Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
usukhbayar_g
Participant

Sharing Threat Emulation Appliance Between Two Security Gateways

We’re currently using a Check Point SandBlast appliance together with our Security Gateway. I’d like to know: is it possible to connect this same SandBlast appliance to another Security Gateway that’s managed by a different Management Server—without giving that team full admin access to our SandBlast?

I saw in the setup guide that the other side needs to create a gateway object and define it as a "TE Appliance." I’m wondering—does doing this give them the same kind of administrative permissions over the appliance that we currently have?

0 Kudos
6 Replies
G_W_Albrecht
Legend Legend
Legend

In https://support.checkpoint.com/results/sk/sk113599 we learn that you can use the TE appliance together with a number of Harmony Endpoint Security servers, so sharing should be possible. I would suggest to contact CP TAC to learn how to configure such a deployment! It looks as if only a certificate for TLS is needed but no SIC that would enable administration tasks from SMS.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
usukhbayar_g
Participant

Does it mean configuring SIC between them would enable administration from the another Management server through SmartConsole, therefore configuring TLS is sufficient to work?

G_W_Albrecht
Legend Legend
Legend

Afaik you can only establish SIC with one SMS ! With SIC established, you have access to the GW/TE appliance by using SMS CLI:

$CPDIR/bin/cprid_util -server <IPv4 Address of appliance> -verbose rexec -rcmd /bin/clish -c "show date"

Seesk101047: How to manage a Security Gateway using the "cprid_util" tool for details!

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
PhoneBoy
Admin
Admin

Looking at sk113599 it's only talking about establishing connectivity with Harmony Endpoint and Harmony Browse.
For a Check Point gateway, I assume the appliance has to be SICed to the same management domain.
Not sure how this would work for an externally managed TE appliance (or if this is even supported).

0 Kudos
Josh28
Contributor

Hello,

Personally I’m using my sandblast with a third-party vendor, as an ICAP server. Maybe someone knows if the Secure Gateways can be configured as a ICAP client?  And then the gateways could declare your sandblast as their Icap server ? It might do the trick.

0 Kudos
_Val_
Admin
Admin

Per documentation, it is indeed possible, see here, for example

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events