CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-01
vvcat vvcat is offline
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default what is different between smartCenter server and enforcement module

Hi,

I am newbiz for the cp fw, what is different between smartcenter server and enforcement module and their function.

I one cp fw is running , how can I check that fw has already been installed enforcement module?
Reply With Quote
  #2 (permalink)  
Old 2008-04-01
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 983
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: what is different between smartCenter server and enforcement module

Check Point consists of 3 tiers or parts

SMARTConsole - The GUI Front End where you define the security policy and login.
SMARTCenter - The Management server that the SMARTConsole connects to and where the security policy is saved.
Enforcment Module - This is the place where the security policy is implemented, where the traffic flows through.

You may find that physically one peice of hardware may hold all 3 parts, but Check Point still runs as though is 3 peices of software.
Reply With Quote
  #3 (permalink)  
Old 2008-04-01
vvcat vvcat is offline
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Re: what is different between smartCenter server and enforcement module

according to your message, enforcement modules should be install, right?
Reply With Quote
  #4 (permalink)  
Old 2008-04-01
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: what is different between smartCenter server and enforcement module

Yes, you will need at least one enforcement module, even if it might be installed in a different machine.

When installing there are 2 main options, Stand Alone and Distributed, when you chose the last one it's possible to install the modules separately.

When testing it's quite frequent to just install everything on the same box.
Reply With Quote
  #5 (permalink)  
Old 2008-04-01
vvcat vvcat is offline
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Re: what is different between smartCenter server and enforcement module

Thanks, If I only have one cp fw NGX, when I install enforcement module, I should choose standalone instead of distributed, right?
Reply With Quote
  #6 (permalink)  
Old 2008-04-01
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 983
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: what is different between smartCenter server and enforcement module

Quote:
Originally Posted by vvcat View Post
Thanks, If I only have one cp fw NGX, when I install enforcement module, I should choose standalone instead of distributed, right?
Stanalone is for where SMARTCenter and Enforcement Software is installed on one box.

Distributed is for where SMARTCenter and Enforcement Software is installed on seperate boxes or where there will be more Enforcement Modules installed later.

If you can spell out exactly how you want the 3 parts of the Check Point system to be installed then we can probably help more fully. At the moment I am not really sure what you are asking, as you only seem to be installing 1 single enforcement mode, where is your SMARTCenter?
Reply With Quote
  #7 (permalink)  
Old 2008-04-01
vvcat vvcat is offline
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Re: what is different between smartCenter server and enforcement module

thanks again, since I have no experience to install cp fw before, so i need to know how many component should I install, but I have experience for netscreen and pix installation.
Reply With Quote
  #8 (permalink)  
Old 2008-04-01
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 983
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: what is different between smartCenter server and enforcement module

You will need ALL of the 3 components to get a working Check Point System. What platform are you installing upon?
Reply With Quote
  #9 (permalink)  
Old 2008-04-01
vvcat vvcat is offline
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Re: what is different between smartCenter server and enforcement module

Nokia IP260 / IPSO 4.2 / R60
Reply With Quote
  #10 (permalink)  
Old 2008-04-02
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: what is different between smartCenter server and enforcement module

OK, do you have any other Check Point boxes? If not, then install as Stand alone. This will install firewall module (enforcement module) and management module (SmartCenter). Then you need to install the GUI (SmartConsole) in a windows PC and connect to the IP 260 to manage it.

If you have more Check Point stuff, there may already be a SmartCenter box that you can use, which might be a better option than running everything on the IP 260. This allow you to have a central repository for logs and config data and manage several firewalls from a single box.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:54.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0