Configuring Services
Configure the applicable services on your Quantum Spark Gateways.
These settings are available when you edit a Plan object (see Plans) and a Gateway object (see Gateways).
You can configure these settings in several ways:
-
Configure the settings in Quantum Spark Management in a Plan object.
Settings in a Plan object apply to all Quantum Spark Gateways that use this Plan.
-
Configure the settings in Quantum Spark Management in a Gateway object (to override the settings in a Plan object).
-
Disable the Quantum Spark Management settings in a Gateway object and configure the local settings on the Quantum Spark Gateway.
Managed Services
Configure the applicable managed services on your Quantum Spark Gateways.
-
From the left navigation panel, click Plans.
-
In the Name column, click the applicable Plan object.
-
In the Plan Edit page, click Services > Managed Services.
-
Select or clear the applicable Managed Services:
Service
Description
Store gateway logs
Sends logs from the Quantum Spark Gateways to Quantum Spark Management.
Send periodic reports
Sends Check Point Executive reports that contain security and network analysis details from Quantum Spark Management to the Quantum Spark Gateway owners.
See Reports.
Firmware upgrades
Controls the firmware upgrades on the Quantum Spark Gateways.
See Firmware.
Backup
Configures where to store the backup of the Quantum Spark Gateway settings and the backup schedule.
See Backup.
Dynamic DNS
Controls the Dynamic DNS settings.
See Dynamic DNS.
Send cloud notifications / Enable events
Sends notifications to the recipients configured on the Services > Notifications page.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable assets data
Enables Assets Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable internet monitoring
Enables Internet Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable VPN monitoring
Enables VPN Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable system monitoring
Enables System Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable users monitoring
Enables Users Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
-
Click Save in the bottom right corner.
-
From the left navigation panel, click Gateways.
-
In the Name column, click the applicable Quantum Spark Gateway object.
-
In the Gateway Edit page, click Services > Managed Services.
-
Click Locked to plan (it must change to Unlocked from plan).
-
Select or clear the applicable Managed Services:
Service
Description
Store gateway logs
Sends logs from the Quantum Spark Gateways to Quantum Spark Management.
Send periodic reports
Sends Check Point Executive reports that contain security and network analysis details from Quantum Spark Management to the Quantum Spark Gateway owners.
See Reports.
Firmware upgrades
Controls the firmware upgrades on the Quantum Spark Gateways.
See Firmware.
Backup
Configures where to store the backup of the Quantum Spark Gateway settings and the backup schedule.
See Backup.
Dynamic DNS
Controls the Dynamic DNS settings.
See Dynamic DNS.
Send cloud notifications / Enable events
Sends notifications to the recipients configured on the Services > Notifications page.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable assets data
Enables Assets Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable internet monitoring
Enables Internet Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable VPN monitoring
Enables VPN Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable system monitoring
Enables System Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
Enable users monitoring
Enables Users Monitoring in Logs & Events.
Note - Requires the Quantum Spark appliance to run the firmware R81.10.10 and higher.
-
Click Save in the bottom right corner.
Firmware
Configure the applicable firmware image and upgrade schedule for your Quantum Spark Gateways.
|
|
Note - The Quantum Spark Gateway reboots after the firmware upgrade. You can limit the firmware upgrade to specified days and hours. The upgrade schedule uses the Quantum Spark Gateway's local time zone. For example, if you configured firmware upgrades to occur between 01:00 am to 06:00 an, then:
|
|
|
Note - You cannot select a Spark version lower than the currently active version. Rollback is not supported. |
-
From the left navigation panel, click Plans.
-
In the Name column, click the applicable Plan object.
-
In the Plan Edit page, click Services > Firmware.
-
In the Select a firmware for all gateways section, select and configure the applicable options:
-
Specific firmware version
You can select
-
In the 1200R Appliance field, select the applicable option.
-
In the 700/1400 Appliance field, select the applicable option.
-
In the 1500/1500R Appliance field, select the applicable option.
-
In the 1600/1800/1900/2000 Appliance field, select the applicable option.
-
-
Check Point recommended
The Quantum Spark Gateways download the recommended firmware version.
-
The firmware version is managed locally on the device
-
Gradual Upgrade
Gradual Upgrade allows you to divide a firmware deployment into multiple stages. In each stage, you choose the percentage of Appliances (connected to a specific plan) that receive the upgrade. You can also set a delay between stages. This minimizes the impact of upgrades and supports progressive deployment.
-
Select the firmware version (refer to the "Specific firmware version" list above).
-
Click Gradual Upgrade Control to open the Gradual Upgrade Control window.
-
In Number of stages, select the number of stages (1 to 5).
-
In each stage, define the percentage of Appliances to upgrade. These Appliances must be connected to the selected plan.
-
In Delay between stages, enter the number of days between each stage.
Note - Stage 1 begins after the delay period, which must be at least 24 hours.
-
Click Start to begin the upgrade process.
Note - This initiates the deployment as per the configured stages and percentages.
-
Click Save to store the configuration.
Important - If you want the deployment to start immediately, you must click Start before clicking Save. You can also click Save without starting the deployment, if you only want to save your settings for later.
-
You can use the following controls to manage the upgrade:
-
-
Stop: Halts the upgrade completely. Devices already upgraded or currently upgrading remain updated. All remaining upgrades are cancelled. To restart, reconfigure and click Start.
-
Pause: Temporarily stops the upgrade. You can later click Start to resume.
Note - You cannot change the configuration while the upgrade is paused.
-
-
In the Schedule firmware upgrades section, select and configure the applicable options:
These options are available only if in the above section you selected "Check Point recommended".
-
Upgrade immediately
-
Daily
-
Weekly
-
Monthly
-
-
Click Save in the bottom right corner.
-
From the left navigation panel, click Gateways.
-
In the Name column, click the applicable Quantum Spark Gateway object.
-
In the Gateway Edit page, click Services > Firmware.
-
In the Select a firmware for this gateway section, select and configure the applicable options:
-
Specific firmware version
-
In the 1200R Appliance field, select the applicable option.
-
In the 700/1400 Appliance field, select the applicable option.
-
In the 1500/1500R Appliance field, select the applicable option.
-
In the 1600/1800/1900/2000 Appliance field, select the applicable option.
-
-
Check Point recommended
The Quantum Spark Gateway downloads the recommended firmware version.
-
The firmware version is managed locally on the device
-
-
In the Schedule firmware upgrades section, select and configure the applicable options:
-
Upgrade immediately
-
Daily
-
Weekly
-
Monthly
-
-
Click Save in the bottom right corner.
|
|
Note - This feature is available only in specific service domains and not globally in all service domains in Quantum Spark Management. |
-
From the left navigation panel, click Plans.
-
In the Name column, click the applicable Plan object.
-
In the Plan Edit page, click Services > Firmware.
-
Click Add Customer Hotfix Firmware.
-
In the Firmware ID field, enter the ID that Check Point provided.
-
Click Finish.
-
In the Select a firmware for all gateways section:
-
Select Specific firmware version.
-
For the applicable appliance models, select this private image.
-
-
Click Save in the bottom right corner.
|
|
Note - This feature is available only in specific service domains and not globally in all service domains in Quantum Spark Management. |
-
From the left navigation panel, click Gateways.
-
In the Name column, click the applicable Quantum Spark Gateway object.
-
In the Gateway Edit page, click Services > Firmware.
-
Click Add Customer Hotfix Firmware.
-
In the Firmware ID field, enter the ID that Check Point provided.
-
Click Finish.
-
In the Select a firmware for all gateways section:
-
Select Specific firmware version.
-
For the applicable appliance models, select this private image.
-
-
Click Save in the bottom right corner.
Backup
Configures where to store the backup of the Quantum Spark Gateway settings and the backup schedule.
The Quantum Spark Gateway saves a backup of its setting in a ZIP file with this naming convention:
|
|
You can upload these backup files:
-
To Check Point Cloud - Quantum Spark Management (recommended).
Notes:
-
Requires the Quantum Spark appliance to run the firmware R81.10.05 and higher.
-
You can save a maximum of 12 backup files.
-
It is not necessary to run a 3rd-party file server.
-
After you select the time interval for periodic cloud backups to occur, the backup file is automatically uploaded to cloud storage.
-
-
To a 3rd-party file server on your network:
-
SFTP
Note - Requires the Quantum Spark appliance to run the firmware R80.20.25 and higher.
-
FTP
Note - Requires the Quantum Spark appliance to run the firmware R80.20.40 and higher.
-
TFTP
-
SCP
Roadmap - Support for SCP is planned.
-
Flash
Roadmap - Support for Flash is planned.
-
-
From the left navigation panel, click Plans.
-
In the Name column, click the applicable Plan object.
-
In the Plan Edit page, click Services > Backup.
-
In the File storage section, select the applicable protocol and configure the required settings.
-
Best Practice: In the File Encryption section, select Use file encryption and configure a password.
-
In the Schedule periodic backup section, select the applicable option:
-
Daily
-
Weekly
-
Monthly
-
-
Click Save in the bottom right corner.
-
From the left navigation panel, click Gateways.
-
In the Name column, click the applicable Quantum Spark Gateway object.
-
In the Gateway Edit page, click Services > Backup.
-
Click Locked to plan (it must change to Unlocked from plan).
-
In the File storage section, select the applicable protocol and configure the required settings.
-
Recommended: In the File Encryption section, select Use file encryption and configure a password.
-
In the Schedule periodic backup section, select the applicable option:
-
Daily
-
Weekly
-
Monthly
-
-
Click Save in the bottom right corner.
-
From the left navigation panel, click Gateways.
-
In the Name column, click the applicable Quantum Spark Gateway object.
-
In the Gateway Edit page, click Services > Backup.
-
In the Protocol, select Cloud.
-
The table with available backups appears at the bottom of the page.
-
Select the backup file and click the Download icon.
Reports
Configures which reports to send and the report schedule.
-
From the left navigation panel, click Plans.
-
In the Name column, click the applicable Plan object.
-
In the Plan Edit page, click Services > Reports.
-
Click Locked to plan (it must change to Unlocked from plan).
-
In the Send periodic report to the following recipients section, select enable the applicable toggles:
-
Send to owner
Sends the report email to the Gateway Owner that is configured in the Gateway object.
-
Additional emails
You can configure additional email recipients.
-
-
In the Report content section:
-
Select the applicable report option:
-
Classic report
Generated by the Quantum Spark Gateway.
-
Extended report
Generated by Quantum Spark Management based on log analysis.
Note - Quantum Spark Gateway reports created in the Quantum Spark Management are deleted after 7 days.
-
-
Optional: If you selected Classic report, then you can enable the toggle Embed report in email message body.
If you disable this toggle, then the report is attached to the email.
-
In the Reports language field, select the applicable option.
-
In the Report time zone field, select the applicable option.
This field is available if you selected Extended report.
You must select the same time zone that is configured on the Quantum Spark Gateways.
-
-
In the Periodic report settings section, select the applicable options:
-
Send daily reports
Note - Requires the Quantum Spark appliance to run the firmware R80.20.40 and higher.
-
Send weekly reports
-
Send monthly reports
If the selected date for the report does not appear in that month (for example, the 31st in a month that only contains 30 days), the report is sent on the last day of the month.
-
-
Click Save in the bottom right corner.
-
From the left navigation panel, click Gateways.
-
In the Name column, click the applicable Quantum Spark Gateway object.
-
In the Gateway Edit page, click Services > Reports.
-
Click Locked to plan (it must change to Unlocked from plan).
-
In the Send periodic report to the following recipients section, select enable the applicable toggles:
-
Send to owner
Sends the report email to the Gateway Owner that is configured in the Gateway object.
-
Additional emails
You can configure additional email recipients.
-
-
In the Report content section:
-
Select the applicable report option:
-
Classic report
Generated by the Quantum Spark Gateway.
-
Extended report
Generated by Quantum Spark Management based on log analysis.
-
-
Optional: If you selected Classic report, then you can enable the toggle Embed report in email message body.
If you disable this toggle, then the report is attached to the email.
-
In the Reports language field, select the applicable option.
-
In the Report time zone field, select the applicable option.
This field is available if you selected Extended report.
You must select the same time zone that is configured on the Quantum Spark Gateways.
-
-
In the Periodic report settings section, select the applicable options:
-
Send daily reports
Note - Requires the Quantum Spark appliance to run the firmware R80.20.40 and higher.
-
Send weekly reports
-
Send monthly reports
If the selected date for the report does not appear in that month (for example, the 31st in a month that only contains 30 days), the report is sent on the last day of the month.
-
-
Click Save in the bottom right corner.
Notifications
Enhanced Notifications provide improved visibility into Gateway events by integrating with Infinity Playblocks. Administrators can receive real-time or aggregated notifications about Gateway events through multiple delivery channels such as email, Microsoft Teams, or Slack.
This feature is supported on Quantum Spark Appliances running R81.10.10 or higher.
Enhanced Notifications include:
-
Real-time alerts
-
Summary alerts based on configurable aggregation intervals
-
Granular control by event type or severity level
-
Recipient management through Playblocks Notifications or additional custom email addresses
-
Centralized delivery configuration using Playblocks Connectors
-
Reuse of Notification Profiles in different Plans for this tenant
To Enable Enhanced Notifications
-
In Quantum Spark Management, select the applicable Plan or Gateway.
-
In the Services section, select Notifications.
-
Click Upgrade to Enhanced notifications.
-
Select Enhanced Notifications powered by Playblocks.
-
Click Finish.
-
Click the Activate button to get started. After successful registration, default notification settings are applied automatically.
Notes:
-
If your account is not yet registered to Playblocks, the system automatically registers it with the Spark Management event automation enabled. No additional license is required. Click here for more information.
-
If you are already registered to Playblocks, the system activates the Spark Management event automation.
-
In both scenarios, the default notification is configured to send all events with Critical or High severity to the Playblocks profile named Immediate attention.
-
To Create a New Notification
-
In the Notifications page. click New to create a notification rule.
-
Optional: In the right panel, enter a name for the notification. Otherwise, the system assigns a default name such as Notification 1, Notification 2, and so on.
-
Select the criteria that trigger the notification:
-
By Severity – Select one or more severity levels.
Note - You cannot select the Information severity. For this severity, you must select By Event.
-
By Event – Click the Add button and select one or more events from the list. A table appears showing all events, including each event’s Family and Severity. Use the free-text search to find specific events, and sort columns by clicking the column name. After selecting your events, click Apply.
Note - Each notification rule can be based on either severity or specific events, not both.
-
-
Click the Recipients tab.
-
Configure recipients using one or more of these options:
-
Playblocks Profiles
-
Click the link provided to open the Playblocks Notification Profiles page and update profiles if necessary.
-
You can select an aggregated profile to receive summary notifications.
-
If you do not wish to send to a Playblocks profile, select No Playblocks profile.
-
Hover over the eye icon to see a preview of the selected Playblocks profile.
-
-
Additional Emails - Enable this option to manually add email addresses. Press "Enter" or click the + icon after each address.
-
-
Make sure you define at least one recipient for each notification.
-
To receive the Gateway description in each notification, go to the Advanced Settings tab and select Include the Gateway description in the notification.
-
Click Save to apply the configuration.
To Update a Notification
-
Click the notification row to open a sidebar.
-
Follow steps 3-7 in the “To create a new notification” procedure.
To Delete a Notification
-
Click the notification row to open a sidebar.
-
Click Delete.
-
Confirm the removal.
Limitations
Enhanced Notifications do not support:
-
Importing or exporting accounts
-
Gateway Owner Objects. You can add this to the Playblocks profile or additional emails
Frequently Asked Questions
Select the frequency in the Playblocks Notifications profile. See here for instructions.
-
Navigate to Plan > Services > Manage Services.
-
Make sure to select the check box for Send cloud notifications / Enable events.
-
Verify that the automation Spark Management Event in Playblocks is activated.
Yes. Recipients can click the unsubscribe link in the notification. The Administrator sees this change in Playblocks Notifications. See here for more information.
Yes. The Administrator can unsubscribe a recipient in the same way described above. See here for more information.
Spark Management supports email, Slack, Teams, and SMS.
|
|
Note - SMS requires an additional Playblocks license. |
Not currently. Each child account must create its own notification profiles.
Configures for which events to generate an email with notification and to which recipients to send this email.
Configuring the 'Notifications' settings in a Plan object
-
From the left navigation panel, click Plans.
-
In the Name column, click the applicable Plan object.
-
In the Plan Edit page, click Services > Notifications.
-
Click Locked to plan (it must change to Unlocked from plan).
-
In the Language field, select the applicable option.
-
Select the applicable notification options:
-
Access Incidents
-
Cluster Incidents
-
System Alerts
-
IoT Events
-
Networking Events
-
Operational Events
-
SD-WAN Events
-
Security Incidents
-
VPN Alerts
-
Other Events
-
-
In the Send email notifications to the following recipients section, select enable the applicable toggles:
-
Send to owner
Sends the report email to the Gateway Owner that is configured in the Gateway object.
-
Additional emails
You can configure additional email recipients.
-
-
Click Save in the bottom right corner.
Configuring the 'Notifications' settings in a Gateway object (to override the Plan settings)
-
From the left navigation panel, click Gateways.
-
In the Name column, click the applicable Quantum Spark Gateway object.
-
In the Gateway Edit page, click Services > Notifications.
-
Click Locked to plan (it must change to Unlocked from plan).
-
In the Language field, select the applicable option.
-
Select the applicable notification options:
-
Access Incidents
-
Cluster Incidents
-
System Alerts
-
IoT Events
-
Networking Events
-
Operational Events
-
SD-WAN Events
-
Security Incidents
-
VPN Alerts
-
Other Events
-
-
In the Send email notifications to the following recipients section, select enable the applicable toggles:
-
Send to owner
Sends the report email to the Gateway Owner that is configured in the Gateway object.
-
Additional emails
You can configure additional email recipients.
-
-
Click Save in the bottom right corner.
Dynamic DNS
Shows the Dynamic DNS primary domain name for this Quantum Spark Gateway.