Print Download PDF Send Feedback

Previous

Next

Post-Installation Configuration

After the installation is complete, and you rebooted the Check Point computer:

The Check Point Configuration Tool lets you configure these settings:

Check Point computer

Commands

Available Configuration Options

Security Management Server,

Dedicated Log Server,

Dedicated SmartEvent Server

cpconfig

(1) Licenses and contracts

(2) Administrator

(3) GUI Clients

(4) SNMP Extension

(5) Random Pool

(6) Certificate Authority

(7) Certificate's Fingerprint

(8) Automatic start of Check Point Products

 

(9) Exit

Multi-Domain Server,

Multi-Domain Log Server

1. mdsenv

2. mdsconfig

(1) Leading VIP Interfaces

(2) Licenses

(3) Random Pool

(4) Groups

(5) Certificate's Fingerprint

(6) Administrators

(7) GUI clients

(8) Automatic Start of Multi-Domain Server

(9) P1Shell

(10) Start Multi-Domain Server Password

(11) IPv6 Support for Multi-Domain Server

(12) IPv6 Support for Existing Domain Management Servers

 

(13) Exit

Security Gateway,

Cluster Member

cpconfig

(1) Licenses and contracts

(2) SNMP Extension

(3) PKCS#11 Token

(4) Random Pool

(5) Secure Internal Communication

(6) Disable cluster membership for this gateway

(7) Enable Check Point Per Virtual System State

(8) Enable Check Point ClusterXL for Bridge Active/Standby

(9) Check Point CoreXL

(10) Automatic start of Check Point Products

 

(11) Exit

Explanation about the Configuration Options on a Security Management Server, dedicated Log Server or SmartEvent Server:

For more information, see the R80.30 Security Management Administration Guide.

Configuration Options

Description

(1) Licenses and contracts

Add or delete licenses and contracts for this server.

(2) Administrator

Configure administrators for this server.

These administrators must have Read/Write permissions to create the first Security Policy

(3) GUI Clients

Configure the computers that are allowed to Connect with SmartConsole to this server.

(4) SNMP Extension

Obsolete. Do not use this option.

(5) Random Pool

Configure the random data to be used for various cryptographic operations on this server.

(6) Certificate Authority

Reset SIC on this server.

(7) Certificate's Fingerprint

Show the SIC certificate's fingerprint for this server.

This fingerprint verifies the identity of this server when you connect to it with SmartConsole for the first time.

(8) Automatic start of Check Point Products

Select which of the installed Check Point products start automatically during boot.

This option is for Check Point Support use.

(9) Exit

Exit from the Check Point Configuration Tool.

Explanation about the Configuration Options on a Multi-Domain Server or Multi-Domain Log Server:

For more information, see the R80.30 Multi-Domain Security Management Administration Guide.

Configuration Options

Description

(1) Leading VIP Interfaces

Configure the Leading VIP Interfaces on this server.

(2) Licenses

Add or delete licenses for this server.

(3) Random Pool

Configure the random data to be used for various cryptographic operations on this server.

(4) Groups

Configure whether to remove group permissions for access and execution on this server.

(5) Certificate's Fingerprint

Show the SIC certificate's fingerprint for this server.

This fingerprint verifies the identity of this server when you connect to it with SmartConsole for the first time.

(6) Administrators

Configure administrators for this server.

These administrators must have Read/Write permissions to create the first Security Policy.

(7) GUI clients

Configure the computers that are allowed to Connect with SmartConsole to this server.

(8) Automatic Start of Multi-Domain Server

Select whether to start the Multi-Domain Server product automatically during boot.

This option is for Check Point Support use.

(9) P1Shell

Enable or disable P1shell.

(10) Start Multi-Domain Server Password

Configure the mdsstart password.

(11) IPv6 Support for Multi-Domain Server

R80.30 Multi-Domain Server does not support IPv6.

Do not use this option (Known Limitation PMTR-14989).

(12) IPv6 Support for Existing Domain Management Servers

R80.30 Multi-Domain Server does not support IPv6.

Do not use this option (Known Limitation PMTR-14989).

(13) Exit

Exit from the Check Point Configuration Tool.

Explanation about the Configuration Options on a Security Gateway or Cluster Member:

Configuration Options

Description

(1) Licenses and contracts

Add or delete licenses and contracts for this computer.

(2) SNMP Extension

Obsolete. Do not use this option.

(3) PKCS#11 Token

Configure a PKCS#11 Token for a VPN cryptographic device.

(4) Random Pool

Configure the random data to be used for various cryptographic operations on this server.

(5) Secure Internal Communication

Reset and configure the one-time activation key (between 4 and 127 characters long) for Secure Internal Communication (SIC) with a Management Server.

For more information, see the R80.30 Security Management Administration Guide.

(6) Enable cluster membership for this gateway

(6) Disable cluster membership for this gateway

Configure this Security Gateway as part of a Check Point cluster.

For more information, see the R80.30 ClusterXL Administration Guide.

(7) Enable Check Point Per Virtual System State

(7) Disable Check Point Per Virtual System State

Configure the VSX Virtual System Load Sharing on this VSX Gateway.

For more information, see the R80.30 VSX Administration Guide

(8) Enable Check Point ClusterXL for Bridge Active/Standby

(8) Disable Check Point ClusterXL for Bridge Active/Standby

Configure this Security Gateway as part of a ClusterXL in Bridge Mode.

For more information, see the R80.30 ClusterXL Administration Guide.

(9) Check Point CoreXL

Configure the CoreXL.

For more information, see the R80.30 Performance Tuning Administration Guide.

(10) Automatic start of Check Point Products

Select which of the installed Check Point products start automatically during boot.

This option is for Check Point Support use.

(11) Exit

Exit from the Check Point Configuration Tool.