- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I am looking for some option to prevent local admin to create rules "on top" of SMP auto -generated rules.
Even if the firewall access policy and URL/App filtering policy configured "manage in SMP" -local admin can still add manual rule with "any-any accept" on topof those rules .
In this case all block rule for "undesired applications " are ineffective.
Any ideas?
Thank you.
Admin is supposed to be able to change policy. But you may create account with "view only" permissions.
Note this requires recent firmware and is NOT currently supported on the 1500 series appliances.
So to be clear, you want to have rules which the device administrator cannot opt out of?
That's what Provider-1's global policies do. You have a "Before" section and an "After" section at the global level. These rules are imposed on the CMAs. Admins at the CMA level cannot make any rules above the "Before" rules from the global policy.
It's also the kind of functionality SMP supports, just not with 1500 gateways (yet, presumably).
And the 1500s can be managed by a SmartCenter, so Provider-1 would work now. 😜
As an aside, does GAiA Embedded have Sofaware bits? I don't think I knew SMP could manage them. Or that SMP was still around, really.
Right, but the question was about SMP.
In the Sofaware days, SMP was both a cloud-based and an on-premise management solution for Safe@/UTM-1 EDGE appliances.
It has since been expanded to manage Embedded Gaia appliances, but we no longer offer it as an on-premise solution.
Now, as to whether there are Sofaware bits in Embedded Gaia, I'd say: highly likely.
We did fully acquire Sofaware, after all. 🙂
Thank you all!
It seems like only Privider-1 management can support full pre and post rules.
SMP portal pre rules are not include applications/url restrictions .
I hope in the future Checkpoint will support pre rules with application control on SMP management.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY