Defining A Smartlsm Gateway Profile For A Large-Scale Deployment; Defining A Smartlsm Appliance Cluster Profile - Infinity CHECK POINT 1100 Administration Manual

Appliances centrally managed
Hide thumbs Also See for CHECK POINT 1100:
Table of Contents

Advertisement

Defining a SmartLSM Gateway Profile for a Large-scale
Deployment
SmartLSM lets you manage a large number of Check Point Appliance gateways from one Security
Management Server. When you use a SmartLSM profile, you reduce the administrative overhead
as you define the gateway properties and policy per profile. The SmartLSM profile is a logical
object that contains the firewall and policy components.
Use SmartDashboard to define a single SmartLSM profile for the Check Point Appliance.
To define a single SmartLSM profile Check Point Appliance:
1. Log in to SmartDashboard with your Security Management credentials.
2. Open the Security Policy that you want to enforce on the Check Point Appliance SmartLSM
Security Gateways.
3. From the Network Objects tree, right-click Check Point and select SmartLSM Profile > Small
Office Appliance Gateway.
The SmartLSM Security Profile window opens.
4. Define the SmartLSM security profile through the navigation tree in this window.
To open the online help for each window, click Help.
5. Click OK and then install the policy.
Note - To activate SmartProvisioning functionality, you must install a security policy on the
LSM profile.
6. Continue in SmartProvisioning

Defining a SmartLSM Appliance Cluster Profile

The SmartLSM Appliance Cluster Profile is a logical object like the SmartLSM Appliance Gateway
profile. It contains the firewall and policy components but also requires logical topology
configuration.
The topology table in the SmartLSM Cluster Profile is a template for all SmartLSM clusters that is
created with this profile. The SmartLSM Cluster Profile automatically assigns the configuration
settings and security policies to the SmartLSM cluster.
The SmartLSM Cluster Profile and its topology are configured in SmartDashboard. Then the
SmartProvisioning SmartConsole GUI is used to connect and manage the appliances by the
Security Management Server.
Before you do the procedure:
Prepare two appliances.
Configure matching internal interfaces with IP addresses in the same subnet. For example, if
you use LAN1 on one of the appliances, you must use LAN1 on the second appliance.
Prepare the WAN interfaces on the same subnet.
Select a random IP address from the WAN and the Internal networks addresses pool to use as
the Cluster Virtual IP.
Check Point 1100/1200R/1400 Appliances Centrally Managed Administration Guide R77.20.70
("Creating a
Gateway" on page 28).
Installation
|
23

Advertisement

Table of Contents
loading

Table of Contents