Configuring the Quantum Edge VNF in SmartConsole
After the service is deployed from the VCO, make sure the status of the deployment in Monitor > Edge.
When the service status is powered on, it is necessary to configure it in Check Point's SmartConsole.
Creating a Quantum Edge Security Gateway Object
To manage and install policies on your Quantum Edge for VMware SD-WAN, use the Check Point SmartConsole.
In SmartConsole, you can select the Wizard Mode or the Classic Mode to create the required object.
Creating a Security Gateway Object – Wizard Mode
To manage and install policies on your Quantum Edge for VMware SD-WAN Gateway, use the Check Point SmartConsole.
-
Go to Object Explorer > More Object Types > Network Objects > Gateways & Servers > New Gateway.
-
Select Wizard Mode.
-
On the General Properties tab, enter this information:
Gateway Name:
The name of the VNF gateway
Gateway platform:
CloudGuard Edge appliances only Gateway IP address:
Enter the VNF IP address
-
Click Next.
-
On the Trusted Communication tab, do this step:
- In Authentication, select Initiate trusted communication securely by using a one-time-password and enter the Activation Key you configured in the VNF deployment.
You can initiate trusted communication at this time. Alternatively, you can initiate trusted communication automatically when the Quantum Edge Gateway connects to the Security Management Server for the first time (Auto Join).
-
To authenticate that the VNF deployed successfully:
In Trusted communication, select Initiate trusted communication now, click Connect > Next.
-
Authenticate that the VNF is uses Auto Join:
In Trusted communication, select Initiate trusted communication automatically when the Gateway connects to the Security Management Server for the first time, click >Next.
-
In Blade Activation, select the blades to be activated, click Next.
-
In Blade Configuration, clear the NAT checkbox, and then click Next > Finish.
-
Click Install policy to push the configuration to the VNF.
Creating a Security Gateway Object – Classic Mode
To manage and install policies on your Quantum Edge for VMware SD-WAN Gateway, use the Check Point SmartConsole.
-
Go to Object Explorer > More Object Types > Network Objects > Gateways & Servers > New Gateway.
-
Select Classic Mode.
-
On the General Properties tab, enter this information:
Gateway Name:
The name of the VNF gateway
Gateway Platform:
CloudGuard Edge appliances only
Gateway IP Address:
Enter the VNF IP Address
-
In the Secure Internal Communication field, click Communication, and then select:
-
In Authentication, select Initiate trusted communication securely by using a one-time-password.
-
Enter the Activation Key you configured in the First Time Configuration Wizard installation.
-
Click OK.
-
-
In the Network Security field, select the Software Blades to be activated.
-
Click OK.
-
Click Install policy to push the configuration to the VNF.
Creating a Quantum Edge Cluster Object
To create a Quantum Edge cluster object and use Check Point's SmartConsole to manage and install policies.
In SmartConsole, you can select the Wizard Mode or the Classic Mode to create the required object.
Creating a Cluster Object – Classic Mode
To manage and install policies on your Quantum Edge for VMware SD-WAN Gateway, use the Check Point SmartConsole.
|
Important - Requires the Check Point Management Server R81 or higher. |
-
Go to Object Explorer > More Object Types > Network Objects > Gateways & Servers > New > Cluster > Small Office Cluster.
-
Select Classic Mode.
-
On the General Properties tab, enter this information:
Cluster Name:
The name of the cluster
Cluster Platform:
CloudGuard Edge appliances only
Cluster IP Address:
Enter a fictitious IP address (such as 0.0.0.0) to represent the cluster
This IP address is not used
-
In the General Properties tab, clear the ClusterXL checkbox.
The ClusterXL tab automatically changes to 3rd Party Configuration.
-
Add the Cluster Members.
Go to Cluster Members > click Add > New Cluster Member.
-
Enter the name and IPv4 address of the first member > click Communication.
-
Enter the Activation Key > click Initialize.
For each member, make sure that the Trust state is Trust established.
-
Do the same steps again to add the second member of the cluster.
-
-
Go to Topology > Edit Topology.
-
Click Get > All members interfaces with Topology.
-
Configure the topology:
-
For the WAN interface, set the Network Objective as Private, and make sure the topology for the WAN interfaces is set to External.
-
For the LAN2 interface, set the Network Objective as 1st Sync, and make sure the topology for the LAN2 interfaces is set to Internal.
-
-
Click OK.
-
Click OK.
-
Publish the SmartConsole session.
-
Install the Access Control policy on the Cluster object.
Creating a Cluster Object – Wizard Mode
To create a Quantum Edge cluster object and use Check Point's SmartConsole to manage and install policies.
-
Go to Object Explorer > More Object Types > Network Objects > Gateways & Servers > New > Cluster > Small Office Cluster.
-
Select Wizard Mode.
-
In the General Properties tab, enter this information:
Cluster Name:
The name of the cluster
Cluster Hardware:
Quantum Edge appliances only
-
Click Next.
-
Add the Cluster Members.
Go to Cluster Members > click Add > New Cluster Member.
-
For each Cluster Member, enter the name of the member and its IP address.
-
Enter the Activation Key > click Next to initialize.
For each member, make sure that the Trust state is Trust established.
-
-
For the WAN interfaces, enter a fictitious IP address (such as 0.0.0.0) to represent the cluster. This IP address is not used. Click Next.
-
To create the cluster, click Finish.
-
Double-click the cluster object.
-
In the General Properties, clear the ClusterXL checkbox.
In the left tree, the ClusterXL pane automatically changes to 3rd Party Configuration.
-
Go to Topology > Edit Topology.
-
Click Get > All members interfaces with Topology.
-
Configure the topology:
-
For the WAN interface, set the Network Objective as Private, and make sure the topology for the WAN interfaces is set to External.
-
For the LAN2 interface, set the Network Objective as 1st Sync, and make sure the topology for the LAN2 interfaces is set to Internal.
-
-
Click OK.
-
Click OK.
-
Publish the SmartConsole session
-
Install the Access Control policy on the Cluster object.