Step 3 - Configuration on Security Gateways

This is a step in the On-Premises Management Deployment.

Part 1 - Prerequisites for Security Gateways

Part 2 - Configuration of SD-WAN interfaces on the Security Gateway

Part 3 - Installation of the Nano-Agent on the Security Gateway

The Nano-Agent connects the Security Gateway / each Cluster Member to Check Point Portal, and enable the automatic installation and update of the SD-WAN policy from Check Point Portal.

There are two possible onboarding options - automatic (recommended) and manual.

Part 4 - Configuration of the Security Gateway object in SmartConsole

Security Policy Installation Using SD-WAN Interface IP Addresses

Starting from R82, Security Management can use SD-WAN interface IP addresses to establish Security Policy installation connectivity.

When Security Policy installation to a Security Gateway fails because the primary management IP address is unreachable, Security Management attempts to establish a TCP connection to the Security Gateway through the IP addresses of its SD-WAN interfaces.

Security Management tries the SD-WAN interface IP addresses in order. If a TCP connection cannot be established through the first SD-WAN interface IP address, Security Management tries the next SD-WAN interface IP address in the list. This process continues until a TCP connection is successfully established or all available SD-WAN interface IP addresses have been tried.

Use Case

In environments where a Security Gateway is connected to multiple ISPs, one or more ISP links might become unavailable.

If the Security Gateway's primary management IP address belongs to an unavailable ISP link, Security Management might be unable to establish the initial TCP connection through that address.

When SD-WAN interfaces are configured on the Security Gateway, Security Management can attempt Security Policy installation through the other SD-WAN interface IP addresses.

If routing is configured correctly on the Security Gateway, the kernel routing table might update the default route to use an available ISP link. In this case, if Security Management establishes a TCP connection through the IP address of an available SD-WAN interface, Security Policy installation traffic can flow symmetrically over that ISP path.

In some environments, traffic from Security Management might enter the Security Gateway through one SD-WAN interface and return through another SD-WAN interface. This traffic flow can also succeed if the ISP path supports asymmetric routing and does not block the traffic.

Updating SD-WAN Interface Information in the Security Management

Security Management learns the SD-WAN interface configuration when the administrator selects Get Interfaces in the Security Gateway object under Network Management > Topology. The retrieved interface information is saved in the Security Management database.

To enable Security Management to use SD-WAN interface IP addresses for Security Policy installation connectivity, select Get Interfaces after SD-WAN interfaces are configured on the Security Gateway.

This action is required only once after the SD-WAN interfaces are configured. The information is saved in the Security Management database and used for future Security Policy installations.

If you add additional SD-WAN interfaces later, select Get Interfaces again to update the saved interface information.

Important:

  • Security Management attempts Security Policy installation only through the SD-WAN interface IP addresses configured in the Security Security Gateway object.
  • If an SD-WAN interface is located behind a NAT device, Security Management does not initiate the connection to the translated NAT IP address. Security Management attempts the connection only to the actual SD-WAN interface IP address configured in the Security Gateway object.
  • This capability applies only to policy installation from Security Management to Security Gateways. It does not apply to Security Gateway monitoring.

Security Gateway Connectivity to Security Management

In some scenarios, the Security Gateway initiates connections to the Security Management Server. For example, the Security Gateway may connect to the Security Management Server to fetch policy, retrieve CRLs, and send logs.

To allow the Security Gateway to use all available external interfaces when connecting to Security Management, configure a valid route to Security Management through each relevant path.

For example, if Security Management is reachable through the Internet, configure either a route to the Security Management Server or a default route through each relevant ISP next hop, with different priorities. If Security Management is reachable only through an MPLS network or another private network, configure the required route through the relevant MPLS or private-network path.

It is recommended to enable next-hop monitoring, such as Ping on or IP Reachability Detection, for each route so that routes remain active only when the relevant path is reachable.

With this routing configuration, if the active path goes down, the Security Gateway can fail over to the next available route and continue to reach Security Management.

Part 5 - Configuration of VPN and Security Policy in SmartConsole

Part 6 - Configuration of Security Policy in SmartConsole

What is Next?

Follow Step 4 - SD-WAN Wizard.