4-39
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 4 Configuring Firewall Devices
Check Point Devices
Add and Configure Check Point Devices in MARS
After you identify and bootstrap the Check Point reporting devices and install the policies that enable
the required traffic flows, you must represent those devices in MARS, which uses this information to
communicate with the devices. When adding a Check Point device, you add two types of devices:
•
Primary management station.
The primary management station represents the SmartCenter server
or CMA that manages other Check Point components. In the web interface, the bases module is
defined as a software application (Check Point Management Console application) running on a host.
•
Child enforcement module.
A child enforcement module is a Check Point component, a firewall
or log server, that is managed by a primary management station. When viewing the Security and
Monitoring Devices list, child enforcement modules appear as children of the hosts that are running
the primary management station.
With these definitions in mind, adding and configuring the Check Point device involves the following:
1.
Define a host that represents the Check Point primary management station, specifying the hostname
and management and reporting IP addresses.
2.
Define all of the interfaces of the host.
3.
Add the correct Check Point software application to the host. This application represents the primary
management station.
4.
Specify the communication settings for the primary management station. These settings include
identifying which access types are allowed (CPMI, LEA or both) and the authentication type and
port to use for each supported access type.
5.
(Optional) Define the settings for secure communications. If the access communication are not
conducted in CLEAR, then you must specify the client and server SIC DNs and identify the
certificate authority.
6.
(Optional) Define the routes used by the firewall running on the primary management station. If a
firewall is running on the primary management station, the route information is required to enable
the path analysis and mitigation features of MARS.
7.
Discover the child enforcement modules and the configuration settings of the primary management
station. Discovery of child enforcement modules includes any log servers and firewalls managed by
the primary management station. MARS discovers configuration settings, such as policies, NAT,
modules, and clusters, as well as event information, such as traffic logs, SmartDefense events, and
user authentication events.
8.
Configure the discovered log servers. To configure these log servers, select the Self option from the
Log Info page associated with each server, and specify the access type settings.
9.
Define any log servers not managed by the primary management station. These servers are used by
one or more of the firewalls that were discovered or by the primary management station.
10.
Edit each firewall child enforcement module to select a log server.
11.
(Optional) Specify an SNMP RO community string for each firewall child enforcement module for
which resource utilization monitoring is desired.
12.
(Optional) Define the routes used by each firewall child enforcement module. Route information is
required to enable the path analysis and mitigation features of MARS.
13.
Click Activate in MARS.
To add a Check Point device in MARS, you must perform the following procedures:
•
Add a Check Point Primary Management Station to MARS, page 4-40