
Greetings to all who continue reading the series about the new generation of NGFW Check Point from the SMB family (1500 series). In we explored the SMP solution (management portal for SMB gateways). Today, I would like to discuss the Smart-1 Cloud portal, which positions itself as a SaaS solution from Check Point, serving as the Management Server in the cloud, making it relevant for any Check Point NGFW. For those who have just joined us, let me remind you of the previously discussed topics: , , .
Let's highlight the main capabilities of Smart-1 Cloud:
- A single centralized management solution for your entire Check Point infrastructure (both virtual and physical gateways of various tiers).
- A unified policy set for all Blades simplifies administration processes (creating/editing rules for various tasks).
- Support for a role-based approach when working with gateway settings. It manages access rights for different network administrators, audit specialists, etc., working simultaneously in the portal.
- Threat monitoring, which provides log retrieval and event viewing in one place.
- Support for API interaction. Users can implement automation processes, simplifying routine daily tasks.
- Web access. It removes limitations regarding support for specific OS, and is intuitive.
Those familiar with Check Point solutions may notice that the main features presented are similar to a dedicated Management Server in your infrastructure. They may be partly right, but with Smart-1 Cloud, the Management Server maintenance is handled by Check Point specialists. This includes: taking backups, monitoring available space on storage, fixing errors, installing the latest software versions. The migration process (transfer of settings) is also simplified.
Licensing
Before exploring the functionality of the cloud management solution, let's review the licensing issues from the official .
Managing a single gateway:

The subscription depends on the selected management blades, there are 3 directions available:
- Management. 50 GB storage, daily 1 GB for logs.
- Management + SmartEvent. 100 GB storage, daily 3 GB for logs, report generation.
- Management + Compliance + SmartEvent. 100 GB storage, 3 GB daily log retention, report generation, security best practice configuration recommendations.
*The choice depends on many factors: type of logs, number of users, traffic volumes.
There is also a subscription for managing 5 gateways. We won't go into detail here — you can always find information in .
Launching Smart-1 Cloud
Anyone can try the solution; to do so, you need to register in Infinity Portal — a cloud service from Check Point, where you can access a trial for the following areas:
- Cloud Protection (CloudGuard SaaS, CloudGuard Native);
- Network Protection (CloudGuard Connect, Smart-1 Cloud, Infinity SOC);
- Endpoint Protection (, SandBlast Agent Cloud Management, Sandblast Mobile).
We will authorize you in the system (new users require registration) and proceed to the Smart-1 Cloud solution:

You will receive a brief overview of the advantages of this solution (Infrastructure management, no installation required, automatic updates).

After filling out the fields, you will need to wait for the account setup to access the portal:

In case of a successful operation, you will receive an email (the one you provided when entering Infinity Portal) with registration information, and you will also be redirected to the Smart-1 Cloud homepage.

Available tabs in the portal include:
- Launch SmartConsole. You can use the installed application on your PC or the web interface.
- Sync with the gateway object.
- Working with logs.
- Settings.
Sync with the gateway
Let's start with syncing the Security Gateway; for this, it needs to be added as an object. Go to the tab "Connect Gateway"

You need to enter a unique gateway name; you can add a comment to the object. After that, click "Register".

A gateway object will appear that needs to be synced with the Management Server by executing CLI commands for the gateway:
- Ensure that the latest JHF (Jumbo Hotfix) is installed on the gateway.
- Set the connection token: set security-gateway maas on auth-token
- Check the status of the sync tunnel:
MaaS Status: Enabled
MaaS Tunnel State: Up
MaaS domain-name:
Service-Identifier.maas.checkpoint.com
Gateway IP for MaaS Communication: 100.64.0.1
After the services for Mass Tunnel have been set up, you need to proceed to install the SIC connection between the gateway and Smart-1 Cloud in Smartconsole. In case of a successful operation, the topology of the gateway will be retrieved; here's an example:

Thus, when using Smart-1 Cloud, the gateway connects to the 'gray' network 10.64.0.1.
I would add that in our setup, the gateway accesses the Internet using NAT; hence, it does not have a public IP address on its interface. However, we can manage it externally. This is another interesting feature of Smart-1 Cloud, which creates a separate management subnet with its own pool of IP addresses.
Conclusion
Once you have successfully added the gateway for management through Smart-1 Cloud, you gain full access, just like in Smart Console. In our setup, we launched the web version, which is essentially a virtual machine running the management client.

You can always learn more about the capabilities of Smart Console and Check Point architecture in our authorial guide. .
For now, that's all; we are looking forward to the final article in the series, where we will touch on performance tuning capabilities of the SMB 1500 series with Gaia 80.20 Embedded installed.
. Stay tuned for updates (, , , , )
Source: habr.com
