Workflow for Deploying CloudGuard Controller
CloudGuard Controller Provisions SDDC services as Virtual Data Centers that provide virtualized computer networking, storage, and security. is a component of the R80.40 Security Management Server
Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server..
|
Note - During the upgrade, CloudGuard Controller does not communicate with the Data Center. Therefore, Data Center objects are not updated on the CloudGuard Controller or the Security Gateways. |
Supported Security Gateways
CloudGuard Controller works with these Security Gateways:
-
R80.10 and higher
-
R77.30
-
R77.20
-
Maestro Security Groups that run R80.20SP and higher
-
Scalable Chassis 40000 / 60000 that run R76SP.50 with the R76SP.50 Jumbo Hotfix Accumulator
Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA. (Take 20 and higher)
|
Important - To use the CloudGuard Controller with R77.20 and R77.30 Security Gateways (with the R77.30 Jumbo Hotfix |
Activating the Identity Awareness Software Blade
Activating Identity Awareness for Security Gateways R80.10 and higher

Step |
Instructions |
||
---|---|---|---|
1 |
Connect with SmartConsole |
||
2 |
From the left navigation panel, click Gateways & Servers. |
||
3 |
Create a new Host object with these settings:
|
||
4 |
Open the applicable Security Gateway |
||
5 |
From the left tree, click the General Properties page. |
||
6 |
On the Network Security tab, select the Identity Awareness Software Blade
|
||
7 |
From the left tree, click the Identity Awareness page. |
||
8 |
Select Identity Web API and click Settings. |
||
9 |
Configure the Identity Web API settings:
|
||
10 |
Click OK. |
||
11 |
Install the Access Control Policy. |
Activating Identity Awareness for Security Gateways R77.30, R77.20, and R76SP.50
-
Enable the Identity Awareness Software Blade
Enable the Identity Awareness Software Blade and select Terminal Servers as the identity source.
Step
Instructions
1
Connect with SmartConsole to the Management Server.
2
From the left navigation panel, click Gateways & Servers.
3
Open the applicable Security Gateway / Cluster object.
4
From the left tree, click General Properties.
5
On the Network Security tab, select the Identity Awareness Software Blade:
-
The Identity Awareness Configuration wizard opens.
-
In the Methods for Acquiring Identity window, clear the AD Query option, if you do not use it.
-
Select Terminal Servers > and click Next.
-
In the Integration with Active Directory window, select I do not wish to configure an Active Directory at this time.
-
Click Next.
-
Click Finish.
6
Click OK.
7
Install the Access Control Policy.
-
-
Enable the communication between the CloudGuard Controller and the Identity Awareness daemon on the Security Gateway
Step
Instructions
1
Connect to the command line on each applicable Security Gateway / each Cluster Member
Security Gateway that is part of a cluster..
On Scalable Chassis, connect to the applicable Security Group.
2
Log in to the Expert mode.
3
On a VSX Gateway
Physical server that hosts VSX virtual networks, including all Virtual Devices that provide the functionality of physical network devices. It holds at least one Virtual System, which is called VS0., go to the context the applicable Virtual System:
vsenv <VSID>
3
Enable the Identity Web API:
pdp api enable