Small-scale Deployment Installation
This chapter contains procedures for defining a gateway or a gateway cluster. Do the procedures that match your requirements, then install the policy.
Small-scale Deployment Workflow
This is the suggested workflow for small-scale deployments:
- Create the necessary gateway or cluster objects for your appliances in SmartDashboard.
- Install the Security Policy in SmartDashboard.
- Configure the relevant appliances with the First Time Configuration Wizard. Alternatively, you can use a USB drive to quickly configure many appliances without the First Time Configuration Wizard. For more details, see Deploying from a USB Drive.
- Manage the appliance settings in SmartProvisioning for the gateway or cluster objects.
Defining a Gateway Object
You can use the SmartDashboard creation wizard to define a Check Point Appliance before or after you configure the appliance on site.
Options to define a gateway object:
- Management First - Define the gateway object in SmartDashboard before you configure and set up the actual appliance on site. This is commonly used for remotely deployed appliances or appliances that connect to the Security Management Server with a dynamic IP (assigned by a DHCP server or an ISP), as the IP is not known at the time of the configuration of the object in SmartDashboard. You can prepare a policy that the appliance pulls when it is configured.
- Gateway First – Configure and set up the Check Point Appliance first. It then tries to communicate with the Security Management Server (if this is configured) at 1 hour intervals. If there is connectivity with the gateway during object creation in SmartDashboard, the wizard can retrieve data from the gateway (such as topology), and then help in configuration.
To define a single gateway object:
- Log in to SmartDashboard using your Security Management credentials.
- From the Network Objects tree, right click and select .
The Check Point Security Gateway Creation window opens.
- Select .
The wizard opens to General Properties.
- Enter a name for the Check Point Appliance object and select the hardware type for the hardware platform.
If the appliance does not appear in the hardware list in the R77.30 SmartDashboard, see sk111292.
- Set the Security Gateway to R77.20.
- Select the or to get the gateway's IP address.
- Click .
To configure a static IP address:
- In the Authentication section, select or.
- If you selected enter a and confirm it. This password is only used to establish the initial trust. Once established, trust is based on security certificates.

|
Important - This password must be identical to the one-time password you define for the appliance in the First Time Configuration Wizard.
|
- In the Trusted Communication section, select or
- Click .
A status window appears.
- Click .
To configure a dynamic IP address:
- In the Gateway Identifier section, select one identifier: , or .
- In the Authentication section, select or
- If you select , enter a and confirm it. This password is only used for establishing the initial trust. Once established, trust is based on security certificates.

|
Important - This password must be identical to the one-time password you define for the appliance in the First Time Configuration Wizard.
|
- Click .
To configure the software blades:
In the Blade Activation page, select the software blades that you want to activate and configure.
To configure blades later:
- Select .
- Click .
To configure blades now:
- Select .
- Select the check boxes next to the blades you want to activate and configure.
- Configure the required options:
- NAT - the checkbox is selected by default.
- QoS - Set the inbound and outbound bandwidth rates.
- IPSec VPN - Make sure that the VPN community has been predefined. If it is a star community, the Check Point Appliance is added as a satellite gateway. Select a VPN community that the Gateway participates in from the list.
- IPS - Select a profile from the list or click to create/edit an IPS profile.
- User Awareness - Complete the wizard pages that open to define the User Awareness acquisition sources. In the Active Directory Servers page of the wizard, make sure to select only AD servers that your gateway works with.
- Click .
To hide the VPN domain:
Select .
Select this option only if you want to hide all internal networks behind this gateway’s external IP. All outgoing traffic from networks behind this gateway to other sites that participate in VPN community will be encrypted.
With this option, connections that are initiated from other sites that are directed to hosts behind this gateway are not encrypted. If you need access to hosts behind this gateway, select other options (define VPN topology) or make sure all traffic from other sites is directed to this gateway's external IP and define corresponding NAT port-forwarding rules, such as: Translate the destination of incoming HTTP connections that are directed to this gateway's external IP to the IP address of a web server behind this gateway.
To create a new VPN domain group:
- Make sure that the option is selected.
- In the field, enter a name for the group.
- From the list, select the applicable objects and click . The objects are added to the VPN domain members list.
To select a predefined VPN domain:
- Click .
- From the list, select the domain.
- Click .
In the Installation Wizard Completion page, you see a summary of the configuration parameters you set.
- If you want to configure more options of the Security Gateway, select .
- Click
The General Properties window of the newly defined object opens.