Connecting R80.30 SmartEvent to R77.xx Multi-Domain Server
You can connect R80.30 SmartEvent components to one or more Domains in an R77.xx Multi-Domain Security Management environment.
This procedure explains how to configure a dedicated server for these components:
- SmartEvent Server and SmartEvent Correlation Unit
Configure SmartEvent to read logs from one domain or a number of domains.
To connect R80.30 SmartEvent Server and SmartEvent Correlation Unit to an R77.xx Multi-Domain Server:
- Open an SSH connection to the Correlation Unit server.
- Run this script:
$RTDIR/scripts/SmartEvent_R80_change_dbsync_mode.sh
- Wait until the script has finished running. This is when
cpstart
has finished and you have a prompt. - Open R77.xx SmartDomain Manager.
- Log in to the Global Domain:
- Create a Check Point Host object for the dedicated server for SmartEvent Server R80.30. Define it with the highest version possible, and ignore the Warning message.
- In the > , select these Management Blades:
- Initialize SIC between the Multi-Domain Server and the new server for SmartEvent R80.30.
- In the page, click .
- Click .
- Click .
- Reassign the global Policy for the Domains that use SmartEvent. For new Domains, create a new global assignment.
- In each Domain Management Server, open SmartDashboard.
- Click > > , on each Domain Management Server and Domain Log Server.
- Wait until the server synchronizes and loads SmartEvent.
- Click .
- Install the Event Policy on the Correlation Unit: menu > > .
See also Advanced Configuration for a dedicated SmartEvent Server that is also a Correlation Unit.
Note - For R77.30 Gateways and lower: activate the firewall session for the network activity report.