Getting Started with SmartProvisioning

  1. In SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., configure the SmartProvisioningClosed Check Point Software Blade on a Management Server (the actual name is "Provisioning") that manages large-scale deployments of Check Point Security Gateways using configuration profiles. Synonyms: Large-Scale Management, SmartLSM, LSM. permission in the applicable Permission Profiles, so the applicable administrators could work with SmartProvisioning.

    See Configuring Administrators in SmartProvisioning.

  2. Enable SmartProvisioning on the Security Management ServerClosed Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server..

    See Activating SmartProvisioning on the Security Management Server.

  3. Enable SmartProvisioning on all Security Gateways, which you wish to manage with SmartProvisioning.

    See Activating SmartProvisioning on a Security Gateway.

  4. Connect with SmartConsole to you Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server..

  5. In SmartConsole, create the required SmartLSM Security Profiles for your Security Gateways.

    See Creating SmartLSM Security Profiles.

    This way you can enable or disable a Software BladeClosed Specific security solution (module): (1) On a Security Gateway, each Software Blade inspects specific characteristics of the traffic (2) On a Management Server, each Software Blade enables different management capabilities. on all Security Gateways that use this profile with one change and one policy installation.

  6. In the SmartConsole top left corner, click Menu > click SmartProvisioning.

  7. If you wish to manage configuration of Security Gateways with a profile, in SmartProvisioning, create the required SmartLSM Provisioning Profiles for your Security Gateways.

    This way you can configure some operating system settings on all Security Gateways that use this profile with one change and one policy push.

  8. Create the required device objects for your Security Gateways.

    Note - You can always assign or remove a SmartLSM ProvisioningClosed Check Point Software Blade on a Management Server that manages large-scale deployments of Check Point Security Gateways using configuration profiles. Synonyms: SmartProvisioning, SmartLSM, Large-Scale Management, LSM. Profile in the Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. object properties.

  9. Open each Security Gateway object and make sure the settings are correct for your environment.

    See:

  10. Optional: If your Security Gateway must participate in a Site to Site VPN, see VPNs and SmartLSM Security Gateways.

  11. In SmartProvisioning, push the settings to the applicable profiles and devices:

    • From the left panel, click Profiles > select a profile > from the top Actions menu, select Push Settings and Actions.

    • From the left panel, click Devices > right-click a device object > click Actions > click Push Settings and Actions > right-click a device object > click Actions > click Push Policy.