Download Complete PDF Send Feedback Print This Page

Previous

Synchronize Contents

Next

Enabling SmartProvisioning

Related Topics

Managing SmartProvisioning Components

Activating SmartProvisioning

Preparing SecurePlatform Gateways

Preparing UTM-1 Edge Gateways

Installing SmartProvisioning SmartConsole

Managing SmartProvisioning Components

SmartProvisioning is an integral part of the Security Management or the Domain Management Server.

To use SmartProvisioning on the Security Management Server or the Domain Management Server, you must obtain and add a SmartProvisioning license to the Security Management Server or Domain Management Server.

Enabling of SmartProvisioning includes configuration of:

  • SmartLSM Security Gateways
  • Corporate Office Gateways
  • Provisioned Gateways
  • SmartProvisioning GUI

Activating SmartProvisioning

SmartProvisioning is an integral part of the Security Management Server or Domain Management Server.

To enable SmartProvisioning on the Security Management Server:

  1. Obtain a SmartProvisioning license. This license is required to activate SmartProvisioning functionality.
  2. Add the license to the Security Management Server or Domain Management Server, with cpconfig or SmartUpdate.

    You can also use the cplic command to add the license.

  3. For Domain Management Server, enable SmartProvisioning and run the command LSMenabler on.

    This message is displayed: Check Point services should be restarted. Restart now (y/n) [y] ?

  4. Enter y to restart the Check Point services.

To verify that SmartProvisioning is enabled:

  1. Connect to the Security Management Server or to the Domain Management Server using SmartDashboard.
  2. Edit the Security Management object.
  3. In the General Properties page of the Security Management object, in the Software Blades section, Management tab, ensure Provisioning is selected. It is selected if the license for SmartProvisioning is installed.

Preparing SecurePlatform Gateways

Preparing SecurePlatform SmartLSM Security Gateways

SmartLSM Security Gateway is a Check Point gateway that has an assigned SmartLSM Security Profile. SmartLSM Security Gateways may, or may not, be enabled for provisioning.

To prepare a SmartLSM Security Gateway:

  1. Make sure that Check Point Security Gateway R60 or higher is installed.
  2. Execute these CLI commands:

    LSMenabler -r on

    cpstop

    cpstart

  3. Open the Check Point Configuration Tool (cpconfig) on the gateway to the ROBO Interfaces page and define an External interface.
  4. Decide whether you want this gateway to be provisioned or not. If this gateway should support provisioning, install SmartProvisioning with the SmartProvisioning Wizard (see SmartProvisioning Wizard - Getting Started).

After completing installation of SmartProvisioning on gateways and the Security Management Server or Domain Management Server, open SmartDashboard and create a Security Policy and SmartLSM Security Profile required by SmartLSM Security Gateways.

To prepare the SmartLSM Security Gateway required objects:

  1. In SmartDashboard select File > New, create a Security Policy and save it.
  2. In the Network Objects tree, right-click Check Point and select SmartLSM Profile > UTM-1/Power-1/Open Server/ IP Series Gateway or 80 series Gateway.
  3. In the SmartLSM Security Profile window, configure the SmartLSM Security Profile, and then click OK.
  4. Install the Security Policy on the SmartLSM Security Profile: Select Policy > Install. In the Install Policy window, select the SmartLSM Security Profile object as an Installation Target.
  5. Click OK.

    Repeat for each SmartLSM Security Profile that you want. If you want to manage gateways of different types (UTM-1 Edge or Security Gateway), you will need a SmartLSM Security Profile for each type.

  6. Close SmartDashboard.
  7. Open SmartProvisioning and add the SmartLSM SecurePlatform gateways. See SmartLSM Security Gateways - Getting Started.

Preparing CO Gateways

A Corporate Office (CO) gateway represents the center of a Star VPN, in which the satellites are SmartLSM Security Gateways. The CO gateway may, or may not, be enabled for provisioning.

To prepare a CO gateway:

  1. On the Check Point Security Gateway, execute the command:
    LSMenabler on
  2. Open SmartDashboard and do the following:
    1. In the VPN tab, right click and select New Community > Star.
    2. In the Star Community Properties window, select Center Gateways and add the CO gateway.
    3. In Satellite Gateways, add SmartLSM Security Profiles as required.
  3. Close SmartDashboard.
  4. In SmartProvisioning, right-click the CO gateway and select Update selected CO Gateway.

Preparing SecurePlatform Gateways

To prepare a SecurePlatform gateway for provisioning:

  1. Ensure that R65 HFA 40 or later is installed.

    If the R65 gateways are not ready to be provisioned, you must manually add the HFA 40 (or later) package for SecurePlatform to the SmartUpdate repository on the Security Management Server or Domain Management Server.

  2. Install SmartProvisioning using the SmartProvisioning Wizard.

Preparing UTM-1 Edge Gateways

A UTM-1 Edge gateway is a Check Point device. It may be a SmartLSM Security Gateway, with an assigned SmartLSM Security Profile, or it may be enabled for Provisioning, or both. Each UTM-1 Edge device is configured with Safe @ or Edge Firmware. Consult with Technical Support for the firmware version needed to support SmartProvisioning.

Configure SmartProvisioning to recognize the firmware of a UTM-1 Edge gateway.

To configure firmware:

  1. In a Devices work space, right-click a UTM-1 Edge gateway and select Edit Gateway.
  2. In the UTM-1 Edge [SmartLSM] Gateway window, select the Firmware tab.
  3. Select the option that describes this UTM-1 Edge SmartLSM Security Gateway.
    • Use default: Firmware defined as Default in SmartUpdate.
    • Use SmartLSM Security Gateway's installed firmware: Firmware currently installed on a UTM-1 Edge SmartLSM Security Gateway.
    • Use the following firmware: Firmware to be uploaded (with SmartUpdate) to the UTM-1 Edge gateway.

Installing SmartProvisioning SmartConsole

After you enable the SmartProvisioning on the Security Management Server or Multi-Domain Server, the SmartProvisioning SmartConsole is provided automatically.

  1. From the Start menu, select Programs > Check Point SmartConsole > SmartProvisioning.
  2. When logging in, provide the IP address of the SmartProvisioning Security Management Server or the Domain Management Server.
 
Top of Page ©2013 Check Point Software Technologies Ltd. All rights reserved. Download Complete PDF Send Feedback Print