{"id":835,"date":"2017-04-01T20:21:00","date_gmt":"2017-04-01T20:21:00","guid":{"rendered":"https:\/\/jay-miah.co.uk\/?p=835"},"modified":"2024-11-17T20:34:45","modified_gmt":"2024-11-17T20:34:45","slug":"835","status":"publish","type":"post","link":"https:\/\/jay-miah.co.uk\/index.php\/835\/","title":{"rendered":"Deploying a Checkpoint Firewall Solution (GAIA-R77.30)"},"content":{"rendered":"<p>Checkpoint is known\u00a0as being a next generation firewall vendor due to being able to support advanced features up to layer 7 of the OSI model, these include \u201cApplication Filtering\u201d, \u201cDeep Packet Inspection(DPI)\u201d, \u201cIPS\u201d, \u201cSSL Inspection\u201d, \u201cAV scanning\u201d, \u201cIdentity Management\u201d, \u201cURL Filtering\u201d and many more.<\/p>\n<p>Checkpoint Firewalls are not zone based Firewalls unlike your Cisco or Juniper. These firewalls can either be physical or virtual. the main differences between the two types is that physical devices have the hardware capability to perform at much higher levels compared to the VM instances. However they all have the same software versions available to run either on physical hardware or \u00a0as a virtual machine.<\/p>\n<p>Checkpoint firewalls are\u00a0managed in a different way in comparison to other vendors, to manage a \u201cSecurity Gateway\u201d you need to use a \u201cManagement Server\u201d, and in order to use the management server you need to use \u201cSmart Tools\u201d, these tools consist of \u201cSmart Dashboard\u201d, Smartview Tracker\u201d, Smartview Monitor\u201d, SmartDomain Manager\u201d and a few others. The tools are normally installed on a workstation which then connects to the management server to create and manage policies. The polices are then installed on the security gateway.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-836 aligncenter\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/cp.jpeg\" alt=\"CP\" width=\"736\" height=\"469\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>You can run a \u201cManagement Server\u201d from a physical firewall appliance, a windows machine or a virtual appliance running the OS GAIA.<\/p>\n<p>The management server in most cases is another GAIA appliance with capability for logging, there are options to deploy a gateway and management server in one appliance, this is known as a distributed deployment.<\/p>\n<p>In this step by step guide we will run through the process of deploying a checkpoint security solution, using R77.30. We will first deploy a \u201cSecurity Management Server\u201d and install the \u201cSmart Tools\u201d on a workstation. Then we will deploy a separate appliance that will be the \u201cSecurity Gateway\u201d and add it into the management server to be able to install security polices. For this Lab we will use VMware ESXI, the same concepts apply to physical firewalls, in most cases they come pre-built with the latest software so its just a matter of assigning a management IP to the device and running through the web GUI configuration.<\/p>\n<p><strong>The Topology:<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1331\" height=\"1072\" class=\"wp-image-837 aligncenter\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/cp-topology.jpeg\" alt=\"CP Topology\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Anchor Links:<\/p>\n<p><a href=\"http:\/\/presspi\/deploying-a-checkpoint-firewall-solution-gaia\/#1\"><strong>Deploy the Management Server<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/presspi\/deploying-a-checkpoint-firewall-solution-gaia\/#2\"><strong>Install the Smart Tools<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/presspi\/deploying-a-checkpoint-firewall-solution-gaia\/#3\"><strong>Deploy the Security Gateway<\/strong><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Lets get started!<\/p>\n<p><strong>Deploy the Management Server<\/strong><br \/>\n<strong>1.<\/strong>\u00a0From vSphere, right click the host and select\u00a0\u201cNew Virtual Machine\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"312\" height=\"368\" class=\"wp-image-838\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/1-1.jpeg\" alt=\"1\" \/><\/p>\n<p><strong>2.\u00a0<\/strong>Click Custom and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-839\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/2-1.jpeg\" alt=\"2\" \/><\/p>\n<p><strong>3.<\/strong>\u00a0Give the VM a name and click\u00a0\u201cNext\u201d\u00a0\u2013 as this will be the management server i have called it\u00a0\u201cCheckpoint MGMT\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-840\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/3-1.jpeg\" alt=\"3\" \/><\/p>\n<p><strong>4.<\/strong>\u00a0Select the data store to store the VM and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-841\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/4-1.jpeg\" alt=\"4\" \/><\/p>\n<p><strong>5.<\/strong>\u00a0Select\u00a0\u201cVirtual Machine Version: 11\u201d\u00a0and click\u00a0\u201cNext\u201d.\u00a0If your ESXI is below version 6 use version 10.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-842\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/5-1.jpeg\" alt=\"5\" \/><\/p>\n<p><strong>6.<\/strong>\u00a0Select\u00a0\u201cLinux\u201d\u00a0as the guest operating system. From the drop down menu select\u00a0\u201cOther Linux (32 bit)\u201d\u00a0as the\u00a0\u201cVersion\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-843\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/6-1.jpeg\" alt=\"6\" \/><\/p>\n<p><strong>7.<\/strong>\u00a0Assign the VM CPU according to the hardware capability of the ESX host. In this case i have assigned\u00a0\u201c2 Virtual sockets\u201d\u00a0and\u00a0\u201c2 Cores per socket\u201d. Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-844\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/7-1.jpeg\" alt=\"7\" \/><\/p>\n<p><strong>8.<\/strong>\u00a0Give the VM a minimum of 4GB RAM and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-845\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/8-1.jpeg\" alt=\"8\" \/><\/p>\n<p><strong>9.<\/strong>\u00a0Give the Management server 1 NIC and assign it to the appropriate VLAN on the inside network. In our case this is\u00a0\u201cVLAN60\u201d, we need to be able to reach this management server from the workstation which will also be on VLAN60 and have the smart tools installed. Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-846\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/9-1.jpeg\" alt=\"9\" \/><\/p>\n<p><strong>10.<\/strong>\u00a0Select\u00a0\u201cLSI Logic Parallel\u201d\u00a0and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-847\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/10-1.jpeg\" alt=\"10\" \/><\/p>\n<p><strong>11.<\/strong>\u00a0Select\u00a0\u201cCreate a new virtual disk\u201d\u00a0and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-848\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/11-1.jpeg\" alt=\"11\" \/><\/p>\n<p><strong>12.<\/strong>\u00a0Specify the size of the disk in GB, make sure the size is at least\u00a0\u201c70GB\u201d\u00a0as the logs will be stored on this device and the disk space could fill up quick. Select\u00a0\u201cThick Provision Lazy Zeroed\u201d\u00a0and Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-849\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/12-1.jpeg\" alt=\"12\" \/><\/p>\n<p><strong>13.<\/strong>\u00a0Select\u00a0\u201cSCSI (0:0)\u201d\u00a0and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-850\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/13-1.jpeg\" alt=\"13\" \/><\/p>\n<p><strong>14.<\/strong>\u00a0At the summary screen, verify all the details are correct, tick\u00a0\u201cEdit the virtual machine settings before completion\u201d\u00a0and click\u00a0\u201cContinue\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-851\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/14-1.jpeg\" alt=\"14\" \/><\/p>\n<p><strong>15.<\/strong>\u00a0From the \u201cVirtual Machine Properties\u201d\u00a0select\u00a0\u201cNew CD\/DVD (adding)\u201d. Tick\u00a0\u201cConnect at power on\u201d\u00a0, select\u00a0\u201cDatastore ISO File\u201d. Click\u00a0\u201cBrowse\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"708\" height=\"632\" class=\"wp-image-852\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/15-1.jpeg\" alt=\"15\" \/><\/p>\n<p><strong>16.<\/strong>\u00a0Browse the datastore and select the Checkpoint ISO image, (This will need to be uploaded prior to creating the VM). Once selected click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"338\" class=\"wp-image-853\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/16-2.jpeg\" alt=\"16\" \/><\/p>\n<p><strong>17.<\/strong>\u00a0The ISO should now be present inside the Datastore ISO File field. Click\u00a0\u201cFinish\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"701\" height=\"449\" class=\"wp-image-854\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/17-1.jpeg\" alt=\"17\" \/><\/p>\n<p><strong>18.<\/strong>\u00a0Once the VM has been created, right click the VM and select\u00a0\u201cOpen Console\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"391\" height=\"393\" class=\"wp-image-855\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/18-1.jpeg\" alt=\"18\" \/><\/p>\n<p><strong>19.<\/strong>\u00a0Click the green\u00a0\u201cPlay\u201d\u00a0button to power on the virtual machine. As the VM boots, it will load the specified checkpoint ISO, select\u00a0\u201cInstall GAIA on this system\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"658\" height=\"597\" class=\"wp-image-856\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/19-1.jpeg\" alt=\"19\" \/><\/p>\n<p><strong>20.<\/strong>\u00a0At the\u00a0\u201cWelcome\u201d\u00a0screen select\u00a0\u201cOK\u201d\u00a0to proceed with the install.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-857\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/20-1.jpeg\" alt=\"20\" \/><\/p>\n<p><strong>21.<\/strong>\u00a0Select\u00a0\u201cUS\u201d\u00a0and click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-858\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/21-1.jpeg\" alt=\"21\" \/><\/p>\n<p><strong>22.<\/strong>\u00a0Allocate 40% of your disk space for \u201cLogs (GB)\u201d and select \u201cOK\u201d in this case 30GB is around 43%.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-859\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/22-1.jpeg\" alt=\"22\" \/><\/p>\n<p><strong>23.<\/strong>\u00a0Create the\u00a0\u201cadmin\u201d\u00a0password and click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-860\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/23-2.jpeg\" alt=\"23\" \/><\/p>\n<p><strong>24.<\/strong>\u00a0Give the Management server an IP address, in this case we have used \u2013\u00a0\u201c10.1.1.2\/24\u201d\u00a0and 10.1.1.1 as the default gateway which will be the setup later as the\u00a0\u201cSecurity Gateway\u201d\u00a0Click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-861\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/25-2.jpeg\" alt=\"25\" \/><\/p>\n<p><strong>25.<\/strong>\u00a0At the confirmation screen click\u00a0\u201cOK\u201d,\u00a0the device will reformat the HDD and install the GAIA OS.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-862\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/26-1.jpeg\" alt=\"26\" \/><\/p>\n<p><strong>26.<\/strong>\u00a0Once installation is complete the device will prompt to\u00a0\u201cReboot\u201d\u00a0click\u00a0\u201cReboot\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-863\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/28-1.jpeg\" alt=\"28\" \/><\/p>\n<p><strong>27.<\/strong>\u00a0once the system as rebooted and is ready it will display the logon prompt<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"200\" class=\"wp-image-864\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/29-1.jpeg\" alt=\"29\" \/><\/p>\n<p><strong>28.<\/strong>\u00a0From a workstation that is able to reach\u00a0\u201cVLAN60\u201d\u00a0Launch a browser and navigate to\u00a0\u201chttps:\/\/10.1.1.2\u201d\u00a0at the warning prompt, click \u201cadvanced\u201d and click\u00a0\u201cProceed to 10.1.1.2 (unsafe)\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1364\" height=\"558\" class=\"wp-image-865\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/30-1.jpeg\" alt=\"30\" \/><\/p>\n<p><strong>29.<\/strong>\u00a0at the login prompt for\u00a0\u201cGAIA\u201d\u00a0use the username\u00a0\u201cadmin\u201d\u00a0and the password that was set at the previous step.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1364\" height=\"571\" class=\"wp-image-866\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/31-1.jpeg\" alt=\"31\" \/><\/p>\n<p><strong>30.<\/strong>\u00a0Once logged in, the device will display a\u00a0\u201cFirst Time Configuration Wizard\u201d\u00a0to complete the initial setup. At the prompt click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"430\" class=\"wp-image-867\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/32-1.jpeg\" alt=\"32\" \/><\/p>\n<p><strong>31.<\/strong>\u00a0Select\u00a0\u201cContinue with Gaia R77.30 configuration\u201d\u00a0and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"430\" class=\"wp-image-868\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/33-1.jpeg\" alt=\"33\" \/><\/p>\n<p><strong>32.<\/strong>\u00a0Verify the IP address details are correct and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"432\" class=\"wp-image-869\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/34-1.jpeg\" alt=\"34\" \/><\/p>\n<p><strong>33.\u00a0<\/strong>Give the device a\u00a0\u201cHost Name\u201d,\u00a0\u201cDomain Name\u201d\u00a0and\u00a0\u201cDNS server\u201d\u00a0details. Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"433\" class=\"wp-image-871\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/36-1.jpeg\" alt=\"36\" \/><\/p>\n<p><strong>34.<\/strong>\u00a0Ensure the time setting are correct and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"572\" height=\"430\" class=\"wp-image-872\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/37-1.jpeg\" alt=\"37\" \/><\/p>\n<p><strong>35.<\/strong>\u00a0Select\u00a0\u201cSecurity Gateway or Security Management\u201d\u00a0Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"569\" height=\"431\" class=\"wp-image-873\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/38-1.jpeg\" alt=\"38\" \/><\/p>\n<p><strong>36.<\/strong> From the checkbox option, select\u00a0\u201cSecurity Management\u201d\u00a0set the device as\u00a0\u201cPrimary\u201d\u00a0and check the\u00a0\u201cAutomatically download Blades Contracts and other important data (highly recommended)\u201d\u00a0box. Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"573\" height=\"433\" class=\"wp-image-874\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/39-1.jpeg\" alt=\"39\" \/><\/p>\n<p><strong>37.<\/strong>\u00a0Create an Administrator user for the\u00a0\u201cManagement Server\u201d\u00a0this account is different to the\u00a0\u201cadmin\u201d\u00a0account. The admin account has privileges for SSH and web GUI access to the device itself, where as the administrator account will be the main account to be used with the\u00a0\u201cSmart Tools\u201d. \u00a0Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"431\" class=\"wp-image-875\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/40-1.jpeg\" alt=\"40\" \/><\/p>\n<p><strong>38.<\/strong>\u00a0At this screen we can define which devices can connect to the\u00a0\u201cManagement Server\u201d\u00a0we can simply allow any IP addresses or a specific subnet. In this case we will only allow the\u00a0\u201c10.1.1.0\/24\u201d\u00a0network. Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"431\" class=\"wp-image-876\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/41-1.jpeg\" alt=\"41\" \/><\/p>\n<p><strong>39.<\/strong>\u00a0Click\u00a0\u201cFinish\u201d\u00a0at the summary screen to begin configuration.This process will take a few minutes to complete.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"433\" class=\"wp-image-877\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/42-1.jpeg\" alt=\"42\" \/><\/p>\n<p><strong>40.<\/strong>\u00a0Once the configuration is complete click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"570\" height=\"432\" class=\"wp-image-878\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/43-1.jpeg\" alt=\"43\" \/><\/p>\n<p><strong>41.<\/strong>\u00a0The device will automatically log in to the web GUI.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1364\" height=\"645\" class=\"wp-image-879\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/44-1.jpeg\" alt=\"44\" \/><\/p>\n<p>The \u201cManagement Server\u201d Installation and configuration is now complete. the next step is to install the smart tools on to a workstation.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Install the Smart Tools<\/strong><\/p>\n<p><strong>1.<\/strong>\u00a0Navigate to the\u00a0\u201cCheckpoint GAIA ISO\u201d\u00a0on the Workstation that will be used to connect to the\u00a0\u201cManagement Server\u201d\u00a0right click the .ISO image and extract the contents to a new folder.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1061\" height=\"722\" class=\"wp-image-880\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/01.jpeg\" alt=\"01\" \/><\/p>\n<p><strong>2.<\/strong>\u00a0Once the files have extracted navigate within the extracted folder into\u00a0\u201cLinux-windows\u201d. Right click\u00a0\u201cSmartConsole\u201d\u00a0and again extract the contents into a new folder.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"603\" height=\"400\" class=\"wp-image-881\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/02.jpeg\" alt=\"02\" \/><\/p>\n<p><strong>3.<\/strong>\u00a0From the extracted contents double click\u00a0\u201cSmartConsole\u201d\u00a0and run the installation wizard. At the Wizard\u00a0\u201cWelcome\u201d\u00a0prompt click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"894\" height=\"591\" class=\"wp-image-882\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/03.jpeg\" alt=\"03\" \/><\/p>\n<p><strong>4.<\/strong>\u00a0At the UAP Click\u00a0\u201cYes\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"381\" class=\"wp-image-883\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/04.jpeg\" alt=\"04\" \/><\/p>\n<p><strong>5.<\/strong>\u00a0Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"381\" class=\"wp-image-884\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/05.jpeg\" alt=\"05\" \/><\/p>\n<p><strong>6.<\/strong>\u00a0Leave the default settings as is to install\u00a0<strong>all<\/strong>\u00a0the smart tools and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"381\" class=\"wp-image-885\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/06.jpeg\" alt=\"06\" \/><\/p>\n<p><strong>7.<\/strong>\u00a0the installation process will begin and take around two mins to complete.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"381\" class=\"wp-image-886\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/07.jpeg\" alt=\"07\" \/><\/p>\n<p><strong>8.<\/strong>\u00a0Once the installation is complete, tick the checkbox\u00a0\u201cAdd Smartconsole shortcuts on desktop\u201d\u00a0and click\u00a0\u201cFinish\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"381\" class=\"wp-image-887\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/08.jpeg\" alt=\"08\" \/><\/p>\n<p><strong>9.<\/strong>\u00a0The tools should now be visible on the desktop.\u00a0Click and launch\u00a0\u201cSmartDashboard\u201d\u00a0form the desktop. this is the main tool used to connect to the management server.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"681\" height=\"768\" class=\"wp-image-888\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/09.jpeg\" alt=\"09\" \/><\/p>\n<p><strong>10.<\/strong>\u00a0At the prompt for login, Specify the\u00a0\u201cAdministrator\u201d\u00a0login details. And use the IP address of the management server,\u00a0\u201c10.1.1.2\u201d. Click\u00a0\u201cLogin\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"284\" height=\"404\" class=\"wp-image-889\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/10-2.jpeg\" alt=\"10\" \/><\/p>\n<p><strong>11.<\/strong>\u00a0The device will display the fingerprint, verify this is correct to ensure you are connecting to the right device.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"284\" height=\"404\" class=\"wp-image-890\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/11-2.jpeg\" alt=\"11\" \/><\/p>\n<p><strong>12.<\/strong>\u00a0Log into the web GUI from a browser at\u00a0\u201chttps:\/\/10.1.1.2\u201d. Navigate to\u00a0\u201cCertificate Authority\u201d\u00a0and verify the fingerprint matches to the one displayed on smart dashboard. \u00a0If this matches (Which it should) click\u00a0\u201cApprove\u201d\u00a0on smart dashboard to connect.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-891\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/12-2.jpeg\" alt=\"12\" \/><\/p>\n<p><strong>13.<\/strong>\u00a0The device will display the trial message. Click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"458\" height=\"172\" class=\"wp-image-892\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/13-2.jpeg\" alt=\"13\" \/><\/p>\n<p><strong>14.<\/strong>\u00a0Once the user is logged in,\u00a0\u201cSmartDashboard\u201d\u00a0will display the the management interface. We can see that there are no\u00a0\u201cSecurity Gateways\u201d\u00a0to manage.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1362\" height=\"727\" class=\"wp-image-893\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/14-2.jpeg\" alt=\"14\" \/><\/p>\n<p>The installation of the \u201cSmartTools\u201d is now complete, using the smartdashboard we are able to access the management server. we use the management server to create policies and configuration we then push these out to \u201cSecurity Gateways\u201d we now need a Security Gateway to manage.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Deploy the Security Gateway<\/strong><\/p>\n<p><strong>1.<\/strong>\u00a0From vSphere, right click the host and select\u00a0\u201cNew Virtual Machine\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"312\" height=\"368\" class=\"wp-image-894\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/1-2.jpeg\" alt=\"1\" \/><\/p>\n<p><strong>2.<\/strong>\u00a0\u00a0Select\u00a0\u201cCustom\u201d\u00a0and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-895\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/2-2.jpeg\" alt=\"2\" \/><\/p>\n<p><strong>3.<\/strong>\u00a0Give the VM a name, In this instance its called\u00a0\u201cCheckpoint-GW-01\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-896\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/3-2.jpeg\" alt=\"3\" \/><\/p>\n<p><strong>4.\u00a0<\/strong>Select the data store to store the VM and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-897\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/4-2.jpeg\" alt=\"4\" \/><\/p>\n<p><strong>5.<\/strong>\u00a0 Select\u00a0\u201cVirtual Machine Version: 11\u201d\u00a0and click\u00a0\u201cNext\u201d.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-898\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/5-2.jpeg\" alt=\"5\" \/><\/p>\n<p><strong>6.\u00a0<\/strong>\u00a0Select\u00a0\u201cLinux\u201d\u00a0as the guest operating system. From the drop down menu select\u00a0\u201cOther Linux (32 bit)\u201d\u00a0as the\u00a0\u201cVersion\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-899\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/6-2.jpeg\" alt=\"6\" \/><\/p>\n<p><strong>7.\u00a0<\/strong>Assign the VM CPU according to the hardware capability of the ESX host. In this case i have assigned\u00a0\u201c2 Virtual sockets\u201d\u00a0and\u00a0\u201c2 Cores per socket\u201d. Click \u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-900\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/7-2.jpeg\" alt=\"7\" \/><\/p>\n<p><strong>8.<\/strong>\u00a0Give the VM a minimum of 4GB RAM and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-901\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/8-2.jpeg\" alt=\"8\" \/><\/p>\n<p><strong>9.<\/strong>\u00a0Give the\u00a0\u201cSecurity Gateway\u201d\u00a03 NIC\u2019s and assign it to the appropriate VLANs. In our case\u00a0\u201cVLAN2\u201d\u00a0will be for the outside network,\u00a0\u201cVLAN60\u201d\u00a0will be for the inside network and\u00a0\u201cVLAN30\u201d\u00a0will be for the DMZ. Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-902\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/9-2.jpeg\" alt=\"9\" \/><\/p>\n<p><strong>10.\u00a0<\/strong>Select\u00a0\u201cLSI Logic Parallel\u201d\u00a0and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-903\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/10-3.jpeg\" alt=\"10\" \/><\/p>\n<p><strong>11.\u00a0<\/strong>Select\u00a0\u201cCreate a new virtual disk\u201d\u00a0and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-904\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/11-3.jpeg\" alt=\"11\" \/><\/p>\n<p><strong>12.<\/strong>\u00a0Specify the size of the disk in GB, make sure the size is at least\u00a0\u201c30GB\u201d\u00a0Select\u00a0\u201cThick Provision Lazy Zeroed\u201d\u00a0and select\u00a0\u201cStore with virtual machine\u201dClick\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-905\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/12-3.jpeg\" alt=\"12\" \/><\/p>\n<p><strong>13.\u00a0<\/strong>Select\u00a0\u201cSCSI (0:0)\u201d\u00a0and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-906\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/13-3.jpeg\" alt=\"13\" \/><\/p>\n<p><strong>14.\u00a0<\/strong>\u00a0At the summary screen, verify all the details are correct, tick\u00a0\u201cEdit the virtual machine settings before completion\u201d\u00a0and click\u00a0\u201cContinue\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"692\" class=\"wp-image-907\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/14-3.jpeg\" alt=\"14\" \/><\/p>\n<p><strong>15.<\/strong>\u00a0From the\u00a0\u201cVirtual Machine Properties\u201d\u00a0select\u00a0\u201cNew CD\/DVD (adding)\u201d. Tick\u00a0\u201cConnect at power on\u201d\u00a0, select\u00a0\u201cDatastore ISO File\u201d. Click\u00a0\u201cBrowse\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"708\" height=\"632\" class=\"wp-image-908\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/15-2.jpeg\" alt=\"15\" \/><\/p>\n<p><strong>16.<\/strong>\u00a0Browse the datastore and select the Checkpoint ISO image. Once selected click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"338\" class=\"wp-image-909\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/16-3.jpeg\" alt=\"16\" \/><\/p>\n<p><strong>17.\u00a0<\/strong>\u00a0The ISO should now be present inside the Datastore ISO File field. Click\u00a0\u201cFinish\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"701\" height=\"449\" class=\"wp-image-910\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/17-2.jpeg\" alt=\"17\" \/><\/p>\n<p><strong>18.<\/strong>\u00a0Once the VM has been created, right click the VM and select\u00a0\u201cOpen Console\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"421\" height=\"394\" class=\"wp-image-911\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/18-2.jpeg\" alt=\"18\" \/><\/p>\n<p><strong>19.\u00a0\u00a0<\/strong>Click the green \u201cPlay\u201d button to power on the virtual machine. As the VM boots, it will load the specified checkpoint ISO, select\u00a0\u201cInstall GAIA on this system\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"658\" height=\"597\" class=\"wp-image-912\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/19-2.jpeg\" alt=\"19\" \/><\/p>\n<p><strong>20.<\/strong>\u00a0At the\u00a0\u201cWelcome\u201d\u00a0screen select\u00a0\u201cOK\u201d\u00a0to proceed with the install.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-913\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/20-2.jpeg\" alt=\"20\" \/><\/p>\n<p><strong>21.\u00a0<\/strong>Select\u00a0\u201cUS\u201d\u00a0and click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-914\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/21-2.jpeg\" alt=\"21\" \/><\/p>\n<p><strong>22.<\/strong>\u00a0Allocate the defaults and select\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-915\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/22-2.jpeg\" alt=\"22\" \/><\/p>\n<p><strong>23.\u00a0<\/strong>Create the\u00a0\u201cadmin\u201d\u00a0password and click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-916\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/23-3.jpeg\" alt=\"23\" \/><\/p>\n<p><strong>24.<\/strong>\u00a0From the menu select\u00a0\u201ceth1\u201d,\u00a0so that this can be configured as the management IP.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-917\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/24-1.jpeg\" alt=\"24\" \/><\/p>\n<p><strong>25.<\/strong>\u00a0The inside network will be\u00a0\u201c10.1.1.0\/24\u201d\u00a0we will use\u00a0\u201c10.1.1.1\/24\u201d\u00a0as the IP. We wont specify a default gateway as its not required- later we can add a static default route via the web GUI as the next hop.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-918\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/25-3.jpeg\" alt=\"25\" \/><\/p>\n<p><strong>26.<\/strong>\u00a0\u00a0At the confirmation screen click\u00a0\u201cOK\u201d, the device will reformat the HDD and install the GAIA OS.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-919\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/26-2.jpeg\" alt=\"26\" \/><\/p>\n<p><strong>27.\u00a0<\/strong>Once installation is complete the device will prompt to\u00a0\u201cReboot\u201d\u00a0click\u00a0\u201cReboot\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"517\" class=\"wp-image-920\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/28-2.jpeg\" alt=\"28\" \/><\/p>\n<p><strong>28.<\/strong>\u00a0Once the system as rebooted and is ready it will display the logon prompt<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"738\" height=\"266\" class=\"wp-image-921\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/29-2.jpeg\" alt=\"29\" \/><\/p>\n<p><strong>29.<\/strong>\u00a0From the workstation launch a browser and navigate to\u00a0\u201chttps:\/\/10.1.1.1\u201d\u00a0at the warning prompt, click\u00a0\u201ccontinue to this webpage (not recommended)\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-922\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-1.jpeg\" alt=\"45.1\" \/><\/p>\n<p><strong>30.<\/strong>\u00a0At the login prompt for \u201cGAIA\u201d use the username\u00a0\u201cadmin\u201d\u00a0and the password that was set at the previous step.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-923\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-2.jpeg\" alt=\"45.2\" \/><\/p>\n<p><strong>31.\u00a0<\/strong>Once logged in, the device will display a\u00a0\u201cFirst Time Configuration Wizard\u201d\u00a0to complete the initial setup. At the prompt click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"430\" class=\"wp-image-924\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/32-2.jpeg\" alt=\"32\" \/><\/p>\n<p><strong>32.\u00a0<\/strong>Select\u00a0\u201cContinue with Gaia R77.30 configuration\u201d\u00a0and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"430\" class=\"wp-image-925\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/33-2.jpeg\" alt=\"33\" \/><\/p>\n<p><strong>33.\u00a0<\/strong>Verify the IP address details are correct and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"572\" height=\"433\" class=\"wp-image-926\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/34-2.jpeg\" alt=\"34\" \/><\/p>\n<p><strong>34.<\/strong>\u00a0leave the settings for \u201ceth0\u201d as default, as we will configure this later via the web GUI. Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"429\" class=\"wp-image-927\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/35-1.jpeg\" alt=\"35\" \/><\/p>\n<p><strong>35.\u00a0<\/strong>Give the device a\u00a0\u201cHost Name\u201d,\u00a0\u201cDomain Name\u201d\u00a0and\u00a0\u201cDNS server\u201d\u00a0details. Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"433\" class=\"wp-image-928\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/36-2.jpeg\" alt=\"36\" \/><\/p>\n<p><strong>36.<\/strong>\u00a0Ensure the time setting are correct and click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"572\" height=\"433\" class=\"wp-image-929\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/37-2.jpeg\" alt=\"37\" \/><\/p>\n<p><strong>37.<\/strong>\u00a0Select\u00a0\u201cSecurity Gateway or Security Management\u201d\u00a0Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"569\" height=\"431\" class=\"wp-image-930\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/38-2.jpeg\" alt=\"38\" \/><\/p>\n<p><strong>38.<\/strong>\u00a0From the checkbox option, select\u00a0\u201cSecurity Gateway\u201d\u00a0and check the\u00a0\u201cAutomatically download Blades Contracts and other important data (highly recommened)\u201d\u00a0box. Click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"570\" height=\"430\" class=\"wp-image-931\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/39-2.jpeg\" alt=\"39\" \/><\/p>\n<p><strong>39.<\/strong>\u00a0Select\u00a0\u201cNo\u201d\u00a0and click click\u00a0\u201cNext\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"431\" class=\"wp-image-932\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/40-2.jpeg\" alt=\"40\" \/><\/p>\n<p><strong>40.<\/strong>\u00a0Enter a one time password for\u00a0\u201cSIC\u201d\u00a0(Secure Internal Communication). This password will be used later when we add the gateway into the \u201cManagement Server\u201d.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"430\" class=\"wp-image-933\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/41-2.jpeg\" alt=\"41\" \/><\/p>\n<p><strong>41.<\/strong>\u00a0Click\u00a0\u201cFinish\u201d\u00a0at the summary screen to begin configuration. This process will take a few minutes to complete.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"569\" height=\"430\" class=\"wp-image-934\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/42-2.jpeg\" alt=\"42\" \/><\/p>\n<p><strong>42.<\/strong>\u00a0Click\u00a0\u201cYes\u201d\u00a0at the prompt.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"453\" height=\"115\" class=\"wp-image-935\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/43-2.jpeg\" alt=\"43\" \/><\/p>\n<p><strong>43.<\/strong>\u00a0Once the configuration is complete, click\u00a0\u201cOK\u201d\u00a0to allow the device to reboot.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"433\" class=\"wp-image-936\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/44-2.jpeg\" alt=\"44\" \/><\/p>\n<p><strong>44.<\/strong>\u00a0The device will reboot, which will take around 2 minutes to complete.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"399\" height=\"98\" class=\"wp-image-937\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-3.jpeg\" alt=\"45\" \/><\/p>\n<p><strong>45.<\/strong>\u00a0Once the device comes back up, from a workstation launch a browser and navigate to\u00a0\u00a0\u201chttps:\/\/10.1.1.1\u201d. Click\u00a0\u201cContinue to this webpage (not recommended)\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-938\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-1-1.jpeg\" alt=\"45.1\" \/><\/p>\n<p><strong>46.<\/strong>\u00a0At the login prompt for\u00a0\u201cGAIA\u201d\u00a0use the username\u00a0\u201cadmin\u201d\u00a0and the password that was set at the previous step.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-939\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-2-1.jpeg\" alt=\"45.2\" \/><\/p>\n<p><strong>47.<\/strong>\u00a0Navigate to\u00a0\u201cNetwork Interfaces\u201d, highlight\u00a0\u201cEth0\u201d\u00a0and click\u00a0\u201cEdit\u201d,\u00a0the status of the interface should be down.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-940\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-3-1.jpeg\" alt=\"45.3\" \/><\/p>\n<p><strong>48.<\/strong>\u00a0Tick\u00a0\u201cEnable\u201d\u00a0give the interface the name\u00a0\u201cOutside Interface\u201d\u00a0and specify the IP address that will be used on the outside. in this case we will use\u00a0\u201c192.168.0.245\/24\u201d. Click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-941\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-4.jpeg\" alt=\"45.4\" \/><\/p>\n<p><strong>49.<\/strong>\u00a0Select\u00a0\u201cEth2\u201d\u00a0and click\u00a0\u201cEdit\u201d.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-942\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-5.jpeg\" alt=\"45.5\" \/><\/p>\n<p><strong>50.<\/strong>\u00a0Tick\u00a0\u201cEnable\u201d\u00a0and give the interface a name. In this instance we will use this as the\u00a0\u201cDMZ interface\u201d. the IP address will be\u00a0\u201c172.16.1.1\/24\u201d. Click\u00a0\u201cOK\u201d.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-943\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-6.jpeg\" alt=\"45.6\" \/><\/p>\n<p><strong>51.<\/strong>\u00a0The status of all 3 interfaces should now be up. the device will automatically save any changes made in the web GUI.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"848\" height=\"633\" class=\"wp-image-944\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/45-7.jpeg\" alt=\"45.7\" \/><\/p>\n<p><strong>52.<\/strong>\u00a0Back on the workstation, from\u00a0\u201cSmartDashboard\u201d\u00a0right click\u00a0\u201cCheckpoint\u201d\u00a0scroll right to\u00a0\u201cCheckpoint\u201d\u00a0and click\u00a0\u201cSecurity Gateway\/Management\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"521\" height=\"227\" class=\"wp-image-945\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/46-1.jpeg\" alt=\"46\" \/><\/p>\n<p><strong>53.<\/strong>\u00a0From the menu select\u00a0\u201cClassic Mode\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"334\" height=\"284\" class=\"wp-image-946\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/47-1.jpeg\" alt=\"47\" \/><\/p>\n<p><strong>54.<\/strong>\u00a0The gateway properties window will appear, insert the host name in the\u00a0\u201cName\u201d\u00a0field, and insert the IP address inside\u00a0\u201cIPv4 Address\u201d. Finally click\u00a0\u201cCommunication\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"761\" height=\"292\" class=\"wp-image-947\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/48-1.jpeg\" alt=\"48\" \/><\/p>\n<p><strong>55.<\/strong>\u00a0Insert the one time password created earlier and click on\u00a0\u201cInitialize\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"542\" height=\"453\" class=\"wp-image-948\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/49-1.jpeg\" alt=\"49\" \/><\/p>\n<p><strong>56.<\/strong>\u00a0Once initialization is complete the page will become grey and a small notice will be displayed as\u00a0\u201cTrust established\u201d. If you encounter any issues at this stage \u2013 the password may need to be reset, use the the following step outlined in this article to complete this. Click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"542\" height=\"453\" class=\"wp-image-949\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/50-1.jpeg\" alt=\"50\" \/><\/p>\n<p><strong>57.<\/strong>\u00a0A window will appear with all the interfaces of the security gateway to indicate this is what has been discovered when the gateway was added and secure communication was established. Click\u00a0\u201cAccept\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"445\" height=\"394\" class=\"wp-image-950\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/51-1.jpeg\" alt=\"51\" \/><\/p>\n<p><strong>58.<\/strong>\u00a0Click\u00a0\u201cOK\u201d\u00a0to close the gateway properties.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"760\" height=\"339\" class=\"wp-image-951\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/52-1.jpeg\" alt=\"52\" \/><\/p>\n<p><strong>59.<\/strong>\u00a0From \u201cSmartDashboard\u201d on the top left select \u201cPolicy\u201d and click the add new rule icon located at the top center.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1362\" height=\"326\" class=\"wp-image-952\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/53-1.jpeg\" alt=\"53\" \/><\/p>\n<p><strong>60.<\/strong>\u00a0An empty rule will appear as shown below, for the time being we don\u2019t need to start creating policies, but we can test the installation of the policy by simply using a blank rule and clicking\u00a0\u201cInstall Policy\u201d\u00a0to ensure it completes successfully. Click\u00a0\u201cInstall Policy\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1362\" height=\"329\" class=\"wp-image-953\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/54-1.jpeg\" alt=\"54\" \/><\/p>\n<p><strong>61.<\/strong>\u00a0At the\u00a0\u201cInstall Policy\u201d\u00a0window click\u00a0\u201cOK\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"622\" height=\"393\" class=\"wp-image-954\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/55-1.jpeg\" alt=\"55\" \/><\/p>\n<p><strong>62.<\/strong>\u00a0the installation of the policy may take a few minutes to complete, and once done it will display a\u00a0\u201cInstallation completed successfully\u201d\u00a0message. Click\u00a0\u201cOK\u201d\u00a0to close the window.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"578\" height=\"432\" class=\"wp-image-955\" src=\"https:\/\/jay-miah.co.uk\/wp-content\/uploads\/2024\/11\/56-1.jpeg\" alt=\"56\" \/><\/p>\n<p>All aspects of the solution is now complete, we have the basics in place from here we can start creating our rule base and NAT policies. The first policy installation has validated that our\u00a0\u201cSmart Tools\u201d,\u00a0\u201cManagement Server\u201d\u00a0and\u00a0\u201cSecurity Gateway\u201d\u00a0are all working and have been setup correctly.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Checkpoint is known\u00a0as being a next generation firewall vendor due to being able to support advanced features up to layer 7 of the OSI model,<\/p>\n","protected":false},"author":1,"featured_media":870,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,6],"tags":[39,54,42,96,98,97],"class_list":["post-835","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-checkpoint-firewall","category-security","tag-checkpoint","tag-gaia","tag-management-server","tag-security-gateway","tag-smart-dashboard","tag-smart-tools"],"_links":{"self":[{"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/comments?post=835"}],"version-history":[{"count":2,"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/835\/revisions"}],"predecessor-version":[{"id":957,"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/835\/revisions\/957"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/media\/870"}],"wp:attachment":[{"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/media?parent=835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/categories?post=835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jay-miah.co.uk\/index.php\/wp-json\/wp\/v2\/tags?post=835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}