Disabling Communication from the Security Gateway to the HSM Server

You can disable communication from the Check Point Security Gateway / ClusterClosed Two or more Check Point Firewalls that work together in a redundant configuration - High Availability, or Load Sharing. Members / Scalable Platform Security GroupClosed A logical group of Security Appliances (in Maestro) / Security Gateway Modules (on Scalable Chassis) that provides Active/Active cluster functionality. A Security Group can contain one or more Security Appliances / Security Gateway Modules. Security Groups work separately and independently from each other. To the production networks, a Security Group appears a single Check Point Firewall. In Maestro, each Security Group contains: (A) Applicable Uplink ports, to which your production networks are connected; (B) Security Appliances (the Maestro Orchestrator determines the applicable Downlink ports automatically); (C) Applicable management port, to which the Check Point Management Server is connected. to an HSM Server. For example, when the HSM Server is under maintenance.

Important:

Step Instructions

1

Connect to the command line on the Security Gateway / each Cluster Member/ Security Group.

2

Log in to the Expert mode.

3

Edit the $FWDIR/conf/hsm_configuration.C file:

vi $FWDIR/conf/hsm_configuration.C

4

Configure the value "no" for the parameter "enabled":

:enabled ("no")

5

Save the changes in the file and exit the editor.

6

On the Scalable Platform Security Group, you must copy the updated file to all Security Group MembersClosed Member of a Security Group in ElasticXL Cluster, Maestro, and Scalable Chassis. Acronym: SGM.:

asg_cp2blades $FWDIR/conf/hsm_configuration.C

7

On the Security Gateway / each Cluster Member / Security Group, restart Check Point services:

cprestart

Important - Traffic does not flow through until the services start.