CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-15
breakdan breakdan is offline
Junior Member
 
Join Date: 2006-12-25
Location: Italy
Posts: 12
Rep Power: 0
breakdan has an average reputation (10+)
Default best way to manage gateway

hi all,

which is (your opinion) best way to manage several gateway with one mgnt?

Is possible to have different policy to load in mgnt for some gateway and, if i need to change policy in other gateways, to open another file anche push policy to these ones?

If yes do you thing is better have a big policy rule with a lots of GW or have different policy smaller (some for GW A/B,E/F anche other for GW C/D,G/H)?

thk a lot and have nice day.

Dan
Reply With Quote
  #2 (permalink)  
Old 2008-03-15
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 861
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: best way to manage gateway

I think it's best to keep it simple to reduce the chance of making mistakes. I'd create a separate policy for each firewall, named in a distinct way so you don't accidentally modify the wrong one. Always set the "Install On" cell with the name of the firewall instead of using "policy targets". That will help keep you from editing the wrong one as well.

If you do try to push policy "A" to firewall "B", FW-1 will warn you that you are about to install a policy with a different name.

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-03-15
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: best way to manage gateway

I'd also recommend selecting installation targets specific to that policy.

In the policy for firewall1 go to the menu up top, Policy>Policy Installation Targets and add only firewall1 to the right side.

In the policy for firewall2 go to the menu up top, Policy>Policy Installation Targets and add only firewall2 to the right side.

etc etc...
Reply With Quote
  #4 (permalink)  
Old 2008-03-15
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: best way to manage gateway

That's what we are doing at my current employment. We use a single
CMA to manage about 30 firewalls, 10 clusters and 10 singles, which works
out quite well so far.
Reply With Quote
  #5 (permalink)  
Old 2008-03-16
breakdan breakdan is offline
Junior Member
 
Join Date: 2006-12-25
Location: Italy
Posts: 12
Rep Power: 0
breakdan has an average reputation (10+)
Default Re: best way to manage gateway

tnk a lot all for useful suggestions

Dan
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:35.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0