Security Profiles for Small Office Appliance Gateways
For more about how to use SmartProvisioning with Check Point Small Office Appliances, visit the Check Point Support Center and search for the relevant appliance to you.
Creating a Small Office Appliance Gateway in SmartProvisioning
Make sure you have a SmartLSM Security Profile for Small Office Appliance gateways defined in SmartConsole before you create a gateway in SmartProvisioning.
To create a new gateway:
- In the navigation tree, click .
- From the Launch Menu, select > > .
The page opens.
- Enter a for the SmartLSM Security Gateway and optional comments. The name cannot contain spaces or non-alphanumeric characters.
- Click .
- In the page, configure these settings:
- - Select the gateway hardware.
- - Select the firmware version of the installed Small Office Appliance.
- - Select the SmartLSM Security Profile to which the Security Gateway is assigned.
- Select to enable gateway management with provisioning configurations.
- Select to enable provisioning without assigning a specific profile.
- Select to assign a provisioning profile to this gateway. Select the provisioning profile from the drop-down list.
- Click .
The page opens.
- In the section, select one of these options:
- . Enter a password, andthen enter it again in the field.
- . Click . The window opens and displays the key in clear text. Save this key to enter it later on the Security Gateway for SIC initialization, and click .
- In the section:
- If you do not know the IP address of the SmartLSM Security Gateway, select .
- If you know the IP address of the SmartLSM Security Gateway, select , and enter the IP address in the field. When you complete this step, the SIC certificate is pushed to the Security Gateway.
Note - The Activation Key sets up Secure Internal Communication (SIC) Trust between the SmartLSM Security Gateway and the Security Management Server. With this SmartLSM wizard, you create the key on the Security Management Server (the SIC certificate and the IKE certificate for the selected gateway are created when you finish this wizard). The certificate is pulled by the gateway when it first connects to the Security Management Server after it is configured with the gateway First Time Configuration Wizard.
- Click .
- Select how to create a VPN certificate:
- To create a VPN certificate from the Internal Check Point CA, select .
- To create a VPN certificate from a third party CA (for example, if your organization already has certificates from an external CA for other devices), clear this checkbox and request the certificate from the appropriate CA server.
- Select to work with the newly created object.
- Clickto complete the SmartLSM Security Gateway creation.