Step 2 - Create a TE Appliance Object in the SmartConsole

  1. Define a Gateway Object
    1. Open SmartConsole.
    2. Go to Gateway > Gateways and Servers > Network Object > New Gateway.

      ../../Images/Gateway_Object.jpg

    3. Select Wizard Mode.

      ../../Images/Wizard_Mode.jpg

    4. In the Gateway platform, select TE Appliances and enable Static IP address.

      ../../Images/Gateway_Platform_TE_Appliances.jpg

      1. Enter the SIC password.

        Note:

        Ensure that the Trust State is Initialized

        ../../Images/Gateway_Name_and_OTP.jpg

    5. Complete the Wizard setup.
  2. Install the Security Policy
    1. In the Gateway Object Properties, navigate to the Threat Prevention tab.
    2. In the Blades section, do these:

      Navigate to the Main Menu in the SmartConsole and click Install Policy for the changes to appear.

      To enable Threat Prevention Features:

      1. In the Custom Threat Prevention section, enable Threat Emulation Blade.

      2. Set the Threat Emulation location to Locally on this Threat Emulation Appliance.

        ../../Images/Locally_on_this_TE_Appliance.jpg

      3. Enable Threat Extraction.

        ../../Images/Enable_Threat_Extraction.jpg

      4. Save and close the settings.

  3. Configure UserCheck Settings on the TE Appliance
    1. To enable HTTPS for the UserCheck Portal, go to TE Appliance Object > UserCheck > Settings.

      Ensure that the URL starts with either an IP address or an FQDN.

    2. By default, the system uses the built-in SSL certificates in SmartConsole. If you want to use your own SSL certificates, navigate to the Certificates section, click Import and upload the valid SSL certificate.
    3. Ensure that the UserCheck portal is enabled to be accessible to all interfaces by navigating to UserCheck settings > Accessibility > Accessible from all interfaces.
      Note:

      This setting enables the Check Point Firewall to receive requests from the Security Management Server via internet. To ensure secure communication, check the configuration of the Threat Prevention API.

    4. Install both policies on the TE Appliance to apply the changes.

      ../../Images/Install_Policies_on_TE_Appliance.jpg