Step 2 - Create a TE Appliance Object in the SmartConsole
-
Define a Gateway Object
- Open SmartConsole.
-
Go to Gateway > Gateways and Servers > Network Object > New Gateway.
../../Images/Gateway_Object.jpg
-
Select Wizard Mode.
../../Images/Wizard_Mode.jpg
-
In the Gateway platform, select TE Appliances and enable Static IP address.
../../Images/Gateway_Platform_TE_Appliances.jpg
-
Enter the SIC password.
Note:Ensure that the Trust State is Initialized
../../Images/Gateway_Name_and_OTP.jpg
-
- Complete the Wizard setup.
-
Install the Security Policy
- In the Gateway Object Properties, navigate to the Threat Prevention tab.
-
In the Blades section, do these:
Navigate to the Main Menu in the SmartConsole and click Install Policy for the changes to appear.
To enable Threat Prevention Features:
-
In the Custom Threat Prevention section, enable Threat Emulation Blade.
-
Set the Threat Emulation location to Locally on this Threat Emulation Appliance.
../../Images/Locally_on_this_TE_Appliance.jpg
-
Enable Threat Extraction.
../../Images/Enable_Threat_Extraction.jpg
-
Save and close the settings.
-
-
Configure UserCheck Settings on the TE Appliance
-
To enable HTTPS for the UserCheck Portal, go to TE Appliance Object > UserCheck > Settings.
Ensure that the URL starts with either an IP address or an FQDN.
- By default, the system uses the built-in SSL certificates in SmartConsole. If you want to use your own SSL certificates, navigate to the Certificates section, click Import and upload the valid SSL certificate.
-
Ensure that the UserCheck portal is enabled to be accessible to all interfaces by navigating to UserCheck settings > Accessibility > Accessible from all interfaces.
Note:
This setting enables the Check Point Firewall to receive requests from the Security Management Server via internet. To ensure secure communication, check the configuration of the Threat Prevention API.
-
Install both policies on the TE
Appliance to apply the changes.
../../Images/Install_Policies_on_TE_Appliance.jpg
-
To enable HTTPS for the UserCheck Portal, go to TE Appliance Object > UserCheck > Settings.