Multi-Domain Security Management Model
With Multi-Domain Security Management, you centrally manage multiple networks, typically of different Domains, divisions, or branches. The Multi-Domain Server is the central management node that controls the policy databases for each of these networks.
Each Domain network is managed by a Domain Management Server, which provides the full functionality of a Security Management Server Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. and can host multiple Virtual Systems, virtual and physical devices. The server that manages the VSX Gateway
Physical server that hosts VSX virtual networks, including all Virtual Devices that provide the functionality of physical network devices. It holds at least one Virtual System, which is called VS0. or VSX
Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Security Gateways and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. Cluster
Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. is the Main Domain Management Server. A VSX Gateway or VSX Gateway can host Virtual Systems that are managed by different Domain Management Servers.
Item |
Description |
1 |
|
2 |
|
3 |
|
4 |
Main Domain Management Server |
5 |
VSX Gateway |
6 |
Virtual Systems in Domain Management Servers |
From a SmartConsole connected to a Multi-Domain Server, provision and configure Domains and Domain Management Servers. Each Domain Management Server uses its own SmartConsole instance to provision and configure its Virtual Systems, Virtual Devices, and policies.