Configure Check Point R81.20

Configure Guardian firewall integration with the Check Point R81.20 firewall.

Make sure that you have:
  • Administrator privileges
  • A valid username and password for authentication
  • Access to the Check Point R81.20 management host
  • The name of the gateway where the rules will be installed
Check Point R81.20 side, this firewall integration:
  • Creates a Check Point R81.20 layer (Nozomi layer) containing the rules
  • Adds the rules to block links and nodes that are unlearned
    Note: If a node or link changes its status to learned, the corresponding rule will be removed.
  • Creates a session named Nozomi Guardian in the firewall to manage rule insertion and removal
  • Generates Check Point R81.20 Service objects for link ports that are not already mapped in the firewall
  • Creates host objects to be used in the block link and nodes rules
  1. In the top navigation bar, select Administration icon - which looks like a gear cog
    The administration page opens.
  2. In the Settings section, select Firewall integration.
    The Firewall integration page opens.
  3. In the top right section, select +
    A dialog shows.
  4. From the Choose firewall dropdown, select Check Point R81.20.
    A dialog shows.
  5. If it is not populated already, in the Host (CA-Emitted TLS Certificate) field, enter the host internet protocol (IP) address.

  6. In the User field, enter your user name.
  7. In the Password field, enter your password.
  8. In the Gateway name field, enter a name.
  9. Optional: Select Enable nodes blocking.
    Enable this option if you want to block nodes.
  10. Optional: Select Enable links blocking.
    Enable this option if you want to block links.
  11. Optional: Select Policies are sent as enabled.
    Make sure that this option is selected so that policies are active upon deployment.
  12. Select Save.
The firewall integration has been configured.