Installation
Check Point 1400 Appliances Centrally Managed Administration Guide R77.20.85 | 23
Defining a SmartLSM Gateway Profile for a Large-scale
Deployment
SmartLSM lets you manage a large number of Check Point Appliance gateways from one Security
Management Server. When you use a SmartLSM profile, you reduce the administrative overhead
as you define the gateway properties and policy per profile. The SmartLSM profile is a logical
object that contains the firewall and policy components.
Use SmartDashboard to define a single SmartLSM profile for the Check Point Appliance.
To define a single SmartLSM profile Check Point Appliance:
1.
Log in to SmartDashboard with your Security Management credentials.
2.
Open the Security Policy that you want to enforce on the Check Point Appliance SmartLSM
Security Gateways.
3.
From the Network Objects tree, right-click
Check Point
and select
SmartLSM Profile
>
Small
Office Appliance Gateway
.
The
SmartLSM Security Profile
window opens.
4.
Define the SmartLSM security profile through the navigation tree in this window.
To open the online help for each window, click
Help
.
5.
Click
OK
and then install the policy.
Note
- To activate SmartProvisioning functionality, you must install a security policy on the
LSM profile.
6.
Continue in SmartProvisioning (on page
Defining a SmartLSM Appliance Cluster Profile
The SmartLSM Appliance Cluster Profile
is a logical object
like the SmartLSM Appliance Gateway
profile. It contains the firewall and policy components but also requires logical topology
configuration.
The topology table in the SmartLSM Cluster Profile is a template for all SmartLSM clusters that is
created with this profile. The SmartLSM Cluster Profile automatically assigns the configuration
settings and security policies to the SmartLSM cluster.
The SmartLSM Cluster Profile and its topology are configured in SmartDashboard. Then the
SmartProvisioning SmartConsole GUI is used to connect and manage the appliances by the
Security Management Server.
Before you do the procedure:
•
Prepare two appliances.
•
Configure matching internal interfaces with IP addresses in the same subnet. For example, if
you use LAN1 on one of the appliances, you must use LAN1 on the second appliance.
•
Prepare the WAN interfaces on the same subnet.
•
Select a random IP address from the WAN and the Internal networks addresses pool to use as
the Cluster Virtual IP.
Summary of Contents for L-71
Page 122: ......