Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RafaelBohrer
Participant
Jump to solution

Setup remote 2530 gateway to be managed centrally by Management Server

Hello all.

I'm trying to setup a 2530 gateway in a remote site but it need be mananged by my central Management Server.

I've tried to use NAT all SIC ports directly to the SMS to connect the 2530 to my SMS. The trust is established, but I can`t fetch the policies.

How is the best practice to setup a remote gateway? I've read many saying to establish site-to-site VPN first. 

Should I first configure 2530 in local mode, set the tunnel and then convert to central management?

Is there any document to help me?

 

 

Here is my topology.

Central Site:

1x 3920 Gateway with SD-WAN enabled. (Gaia 82.10 JHT19)

  • 3 external connections
    • 1 directly connect with public IP
    • 2 behind a ISP modem with internal IP addresses 

1x Management Server with 1 internal IP address (Smart Console 82.10)

 

Remote Site

1x 2530 Gateway just with the initial setup done. (Gaia 82)

  • 1 external connection behind ISP modem with DMZ configured to send to 2530 gateway IP
  • 1 fixed public IP address

 

Regards.

Rafael Bohrer

0 Kudos
1 Solution

Accepted Solutions
Alex-
MVP Silver
MVP Silver

You should consider "Management behind NAT", which also correctly populates the masters file on the remote gateway.

https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityManagement_AdminGuid...

 

View solution in original post

6 Replies
Alex-
MVP Silver
MVP Silver

You should consider "Management behind NAT", which also correctly populates the masters file on the remote gateway.

https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityManagement_AdminGuid...

 

RafaelBohrer
Participant

Thanks Alex. I`ll check it out. 

0 Kudos
RafaelBohrer
Participant

Hello Alex.

I've followed the steps from the documentation. The 2530 established the communication, but still dot fetching the policies.

Here's the error message on 2530 WebGui

Captura de Tela 2026-06-08 às 11.13.13.png

 Any thing that  I'm missing?

 

Regards.

0 Kudos
Alex-
MVP Silver
MVP Silver

You can reset the SIC on the SMS and set it to wait for first contact, then install the policy on your gateway object. Check the first option on the install screen, "install independently..." and uncheck the "if it fails on one gateway..." then proceed.

From the WebUI of the Spark, reinitialize SIC with the password you set in the manager.

0 Kudos
RafaelBohrer
Participant

Still not working, but now this message on Test SIC Connection in SmartConsole

SIC Status for SC-CPFW-01: Unknown

Could not establish TCP connection with 179.219.xxx.xxx

** Please make sure that Check Point Services are running on SC-CPFW-01 and that TCP connectivity is allowed from Security Management Server to IP 179.219.xxx.xxx, Port 18191 **

0 Kudos
RafaelBohrer
Participant

Hello all.

I found the problem. As I have multiple WAN links and SD-WAN enabled, the 3920 was reciving the communication in WAN1, but was responding using WAN2. I fixed the route and it worked.

Thanks for all help.

Regads.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events