- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We’re currently using a Check Point SandBlast appliance together with our Security Gateway. I’d like to know: is it possible to connect this same SandBlast appliance to another Security Gateway that’s managed by a different Management Server—without giving that team full admin access to our SandBlast?
I saw in the setup guide that the other side needs to create a gateway object and define it as a "TE Appliance." I’m wondering—does doing this give them the same kind of administrative permissions over the appliance that we currently have?
In https://support.checkpoint.com/results/sk/sk113599 we learn that you can use the TE appliance together with a number of Harmony Endpoint Security servers, so sharing should be possible. I would suggest to contact CP TAC to learn how to configure such a deployment! It looks as if only a certificate for TLS is needed but no SIC that would enable administration tasks from SMS.
Does it mean configuring SIC between them would enable administration from the another Management server through SmartConsole, therefore configuring TLS is sufficient to work?
Afaik you can only establish SIC with one SMS ! With SIC established, you have access to the GW/TE appliance by using SMS CLI:
$CPDIR/bin/cprid_util -server <IPv4 Address of appliance> -verbose rexec -rcmd /bin/clish -c "show date"
Seesk101047: How to manage a Security Gateway using the "cprid_util" tool for details!
Looking at sk113599 it's only talking about establishing connectivity with Harmony Endpoint and Harmony Browse.
For a Check Point gateway, I assume the appliance has to be SICed to the same management domain.
Not sure how this would work for an externally managed TE appliance (or if this is even supported).
Hello,
Personally I’m using my sandblast with a third-party vendor, as an ICAP server. Maybe someone knows if the Secure Gateways can be configured as a ICAP client? And then the gateways could declare your sandblast as their Icap server ? It might do the trick.
Per documentation, it is indeed possible, see here, for example
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 17 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY