Re: Management over the internet mogwai in the past I have used Smartcenter server in the UK to manage nokia devices in Italy, Spain, Israel and Sweden and all worked very well with no noticable latency problems when pushing policies / pulling logs. Obviously you're talking UK - Australia so there will be more latency, but assuming you have a big enough internet connection at each end I don't think you will have any major issues. Checkpoint encourage you to have a distributed environment with one central smartcenter server as it takes the load off the enforcement modules (ie the devices at the other offices don't have any management functions to perform so they can concentrate on purely blocking / passing traffic. You could install Smartcenter server at each location but it will cost you for each licence (even a secondary 'redundent' server will need a licence). I suggest you:- 1. Setup management server in UK. 2. Make sure you have adequate bandwidth at each location. 3. Install CHKP as enforcement modules at other locations. 4. Ensure you have a backdoor into the remote sites because if you lose UK internet connection / remote site VPN you will not be able to manage these devices. Personally, I would enable the modem on each device for callback and simply unplug the line at the remote site. If you need to use it, is a lot easier to ask someone to plug the line in for you than talk someone through fw unloadlocal etc (especially if they don't speak your language - trust me I've been there :(! Hope the above helps. |