R75.

20

Release Notes

5 October 2011

Classification: [Public]

© 2011 Check Point Software Technologies Ltd. All rights reserved. This product and related documentation are protected by copyright and distributed under licensing restricting their use, copying, distribution, and decompilation. No part of this product or related documentation may be reproduced in any form or by any means without prior written authorization of Check Point. While every precaution has been taken in the preparation of this book, Check Point assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice. RESTRICTED RIGHTS LEGEND: Use, duplication, or disclosure by the government is subject to restrictions as set forth in subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS 252.227-7013 and FAR 52.227-19. TRADEMARKS: Refer to the Copyright page (http://www.checkpoint.com/copyright.html) for a list of our trademarks. Refer to the Third Party copyright notices (http://www.checkpoint.com/3rd_party_copyright.html) for a list of relevant copyrights and third-party licenses.

Please help us by sending your comments (mailto:cp_techpub_feedback@checkpoint.com/documentation_download?ID=12414 For additional technical information. stability fixes. Added instructions for upgrading via CLI ("Upgrade Package via CLI" on page 16) Added Multi-Domain Security Management to products that the new Uninstall does not remove Added Windows Server 2008 R2 to list of supported OS versions Fixed documentation of build numbers to show only the verification output part of the number First release of this document 28 September 2011 29 August 2011 17 August 2011 16 August 2011 4 August 2011 2 August 2011 Feedback Check Point is engaged in a continuous effort to improve its documentation.com?subject=Feedback on R75. security enhancements and protection against new and evolving attacks. visit the Check Point Support Center (http://supportcenter.Important Information Latest Software We recommend that you install the most recent software release to stay up-to-date with the latest functional improvements. Revision History Date 05 October 2011 Description Clarified IP appliance requirements ("Security Software Containers" on page 11) and 64-bit support on Windows ("Security Management Software Blades" on page 14).checkpoint. Latest Documentation The latest version of this document is at: http://supportcontent. Added warning for UTM-1 Edge and Safe@ devices that use locally configured VPN connections with download configuration settings ("Compatibility with Gateways and Endpoint Clients" on page 16).com).checkpoint. .20 Release Notes).

..............................................................................................................25 ...........................................23 SmartEvent Requirements..............................................................................................................................................................................16 IPS-1 Upgrade Paths and Interoperability ......................................................5 Important Solutions............ 8 SmartDashboard ...........................................................15 Upgrade Paths and Interoperability .................................................................................................................................................17 IPSO ................................................17 Linux .......................22 SmartConsole and SmartDomain Manager Hardware Requirements .............................................................................................................24 Optimizing SmartReporter Performance ........................................................11 Security Gateway Software Blades .......................................................................................................................................................................................................................................................................................................10 Supported Security Products by Platform ........... 9 Supported Products .........23 Multi-Domain Security Management Resource Consumption ................................20 Minimum System Requirements ....................................... 8 SmartEvent ...................................... 6 Application Control Software Blade .......11 Security Software Containers...................................16 Platform Requirements ....................................................................................................................................6 URL Filtering Software Blade .....................................................................18 Microsoft Windows .........................15 Compatibility with Gateways and Endpoint Clients ..............23 SmartReporter Requirements ................................. 7 Mobile Access and IPSec Software Blades ........................22 Multi-Domain Security Management Requirements ......................3 Introduction to R75...................................................................................... 7 HTTPS Inspection .................................................. 8 Minor Release Content ...........................................................................................................................................................................................13 Security Management Software Blades ....................................................24 Uninstalling ....................................................................................................................................................................................................................21 Security Gateway Hardware Requirements ............... 5 What's New ...................................18 Solaris ...............................................21 Security Management Hardware Requirements ...........................................................................................................................................15 Supported Management and Gateway Upgrade Paths ............................................................................................................................................................ 7 Identity Awareness Software Blade ..................................................... 6 DLP Software Blade .Contents Important Information ......................................................................................................................................................16 Upgrade Package via CLI ................................................. 8 SmartView Tracker ................... 7 SmartEvent Overview Customization ..............................................................................................................................................................................................................................................................................................................................14 Clients and Consoles by Windows Platform .......................19 Maximum Number of Interfaces Supported by Platform ......................................................... 8 Management Servers ...............................9 IPS Software Blade License Enforcement.............................................................24 Performance Pack ..20 ......................................17 SecurePlatform...................... 9 Build Numbers ............15 Abra Secure Portable Workspace.......................................................... 8 Uninstall Utility ...................................................................................................................................................................................................................................................

Introduction to R75.10 or higher must have a valid Software Blades license. Please read this document carefully before installing R75.20.com/solutions?id=sk64361). see the Known Limitations (http://supportcontent.com/solutions?id=sk64362).20 Page 5 .checkpoint.20 Thank you for installing Check Point version R75.checkpoint.Important Solutions Introduction to R75. This procedure is optional for Multi-Domain Servers and Domain Management Servers. see Software Blade Migration (http://www.checkpoint.Check Point software versions R75.20 Home Page (http://supportcontent.html) or contact Account Services. Important Solutions For more about R75.20 and to download the software.20. If you manage IPv6 or GX gateways from a Security Management server. For a list of open issues. Important . Users with NGX licenses cannot install the software. go to the R75. you must regenerate your IPv6 and GX licenses in the User Center to be compliant with Software Blades. To migrate NGX licenses to Software Blades licenses.com/products/promo/software-blades/upgrade/index.

User Check lets Security Gateways communicate with end users using the new "Inform" and "Ask" actions. including IPSO and Windows. User Check lets Security Gateways communicate with end users using the new "Inform" and "Ask" actions.The term tags is changed to categories. integrating with Identity Awareness.URL Filtering Software Blade What's New In This Section URL Filtering Software Blade Application Control Software Blade DLP Software Blade Identity Awareness Software Blade Mobile Access and IPSec Software Blades HTTPS Inspection SmartEvent Overview Customization SmartDashboard SmartView Tracker SmartEvent Management Servers Uninstall Utility Minor Release Content 6 6 7 7 7 7 8 8 8 8 8 8 9 URL Filtering Software Blade         Integrated Rule Base for URL Filtering and Application Control policies. New tracking options: Extended Log and Complete Log for auditing all URLs accessed during a Web session. Note . Download predefined application and category definitions from the Check Point Web site. Lets users define new custom sites. Lets users define new custom applications. You can define URL Filtering policies with granularity at the user and user group levels. Application Control Software Blade      Integrated Rule Base for URL Filtering and Application Control policies. Cloud-based URL Filtering service dynamically categorizes Web traffic. What's New Page 6 . Enhanced URL Filtering integration with SmartEvent and SmartReporter. URL Filtering is supported on more platforms. New tracking options: Extended Log and Complete Log for auditing all URLs accessed during a Web session.

New option to ignore empty templates during scanning. DLP-1 2571/9571 appliances have standalone and full high availability modes. What's New Page 7 . concurrent connections and throughput). Dynamically load many templates into one data type. DLP. in addition to the fail open NIC option. HTTPS inspection is supported on IPSO and SecurePlatform. Users can have more than one user certificate for authentication with VPN clients. HTTPS Policies now include custom sites and URL Filtering categories. Integrated into relevant event views and cards. Improved performance and high availability: 150 new out-of-the-box data types (total of 500 data types) make it easier to get started.  More methods to prevent unintentional exposure of administrators to sensitive data:    Enhanced template data types:    Custom data types and other enhancements to the CPcode scripting language. Anti-Virus. Mobile Access and IPSec Software Blades R75.DLP Software Blade DLP Software Blade  Enhanced email and Web enforcement:           Prevents data loss from HTTP/S traffic. or the Mobile Access portal. Hide credit card numbers by showing only the last 4 digits in the logs. HTTPS Inspection        Inspection of HTTPS/SSL traffic from enterprise networks to external destinations. Scans outgoing TLS (SMTPS) encrypted email using the Check Point Microsoft Exchange agent. Web traffic performance improvements (connection rate. ClusterXL load sharing (detect only). URL Filtering and Application Control Software Blades. Inspects email messages between internal users and groups in an organization using the Check Point Microsoft Exchange agent.20 supports VPN authentication from many different devices. including logs for IPS. iPhone. Identity Awareness Software Blade  Identity Acquisition (AD Query. Logging enhancements. New predefined queries. iPad. Granular inspection settings for different Software Blades. DLP HTTP/S inspection for non-standard ports. Administrators can send or discard quarantined email using SmartView Tracker and SmartEvent. Enhanced visibility and administrative tools:   Rich DLP status and statistics for SmartDashboard and SmartView Monitor. such as Gmail and Facebook. Granular administrator permissions give more control over who can see DLP data. Identity Agents and Captive Portal) is supported on IPSO platforms.

Different procedures for configuring expiration dates. moving and resizing panels. and URL Filtering). SmartView Tracker   User names are shown by default for administrators with Read/Write permissions. You can choose if identities are shown or hidden by default for customized administrators.20 includes a new command line utility that silently uninstalls the old release ("Uninstalling" on page 25).To uninstall an old release on SecurePlatform.     User and administrator expiration enhancements. DLP. SmartEvent   User names are shown by default for administrators with Read/Write permissions. You can choose if identities are shown or hidden by default for customized administrators.SmartEvent Overview Customization SmartEvent Overview Customization   You can customize your Overview window by adding. it was necessary to uninstall each major release package separately. Administrators currently logged in using the Read Only mode can receive a notification when the Read/Write access mode is available. Notifications for expired and about to expire Users/Administrators. New Permissions Profiles for Multi-Domain Security Management. Management Servers These new features are in the Security Management Server and the Multi-Domain Server. SmartDashboard   Administrators can easily change the SmartDashboard access mode without closing and restarting SmartDashboard.20. You can change between different preconfigured overviews for different Software Blades (IPS. configuring. Uninstall Utility Before R75. deleting. R75. What's New Page 8 . use the Backup and Revert functionality. The uninstall Utility is available for:     Windows Linux IPSO Solaris Note .

To manage your contracts.com/documentation_download?ID=11714) R75.Minor Release Content Minor Release Content This release includes fixes and improvements that were initially included in R71. valid IPS contract that is renewed annually. see sk44175 (http://supportcontent. you must regenerate your IPv6 and GX licenses in the User Center to be compliant with Software Blades. IPS continues to operate using the R70 (Q1/2009) signature set.Check Point software versions R75.checkpoint. go to your UserCenter account or contact your reseller. Users with NGX licenses cannot install the software.30 Release notes (http://supportcontent.  Notifications that IPS service contracts are expiring show in many locations.checkpoint.10 Release notes (http://supportcontent. Supported Products Page 9 .com/documentation_download?ID=12081) Supported Products In This Section Build Numbers Supported Security Products by Platform Clients and Consoles by Windows Platform Abra Secure Portable Workspace Upgrade Paths and Interoperability 10 11 15 15 15 Important .30 and R75. This procedure is optional for Multi-Domain Servers and Domain Management Servers. IPS Software Blade License Enforcement Security Gateways with IPS Software Blades must have a current.10. For more about IPS contract enforcement. For more information. see:   R71.checkpoint.com/solutions?id=sk44175).html) or contact Account Services.checkpoint. Renew your IPS service contract to download and use the current signature set. including:     The IPS SmartDashboard window SmartUpdate Product reports in your Check Point UserCenter account If your service contract has expired. If you manage IPv6 or GX gateways from a Security Management server. To migrate NGX licenses to Software Blades licenses.10 or higher must have a valid Software Blades license. see Software Blade Migration (http://www.com/products/promo/software-blades/upgrade/index.

60. Software Blade / Product Security Gateway Security Management SmartConsole Applications Build Number 274 080 983000411 Verifying Build Number fw ver fwm ver Help > About Check Point <Application name> cvpn_ver fwm mds ver Help > About Check Point Multi-Domain Security Management ver sim ver -k Mobile Access Multi-Domain Server SmartDomain Manager 163 214 983000230 SecurePlatform Acceleration (Performance Pack) Advanced Networking (Routing) Server Monitoring (SVM Server) Management Portal 095 017 007 gated -ver 008 015 rtm ver cpvinfo /opt/CPportalR75/portal/bin/smartportalstart SVRServer ver About SmartReporter Endpoint Security Server Compatibility Packages CPNGXCMP-Flow-00 CPV40Cmp-Flow-00 CPEdgecmp-Flow-00 CPCON66CMP-Flow-00 fl_cmp Fox_Cmp CPSG80CMP-Flow-00 219 7.20 software products and their build numbers as included on the product DVD.Build Numbers Build Numbers This table shows the R75. To verify each product build number.302. use the show command syntax or do the steps in the GUI.000 002 006 004 001 008 016 005 /opt/CPNGXCMP-R75/bin/fw_loader ver /opt/CPV40Cmp-R75/bin/fw_loader ver /opt/CPEdgecmp-R75/bin/fw ver /opt/CPCON66CMP-R75/bin/fw_loader ver /opt/CPSG80CMP-R75/bin/fw_loader ver Supported Products Page 10 .

5. IP690. IPS and VPN blades only. Supported Products Page 11 . and IP560 flash-based appliances. 150) Software Blade Containers Other Platforms and Operating Systems For more about supported operating system versions. refer to Operating System Versions (on page 12). IP560. 50) Power-1 UTM-1 IPSO IPSO Disk-based Flash-based   1      (50. Microsoft Windows Server 2003. 9. 2G of RAM is required on IP290. IP1280. 1G of RAM is enough to run Firewall. Security Software Containers Software containers are supported on these operating systems and platforms.4   Crossbeam X-series Solaris Ultra-SPARC 8. 25. IP390. The supported IP Appliances models are IP150.0. On Flash-based Appliances. IP390. 2. 3. We do not recommend that you install Multi-Domain Security Management on Sun T-Series servers.Supported Security Products by Platform Supported Security Products by Platform These tables show the security products related to this release and on which platforms they are supported. and IP2450. 2008 Windows XP. We recommend that you install Multi-Domain Security Management on Sun M-Series servers. 10  Security Management Security Gateway Multi-Domain Security Management  3    2 Notes about Security Software Containers 1. To activate more blades. 7  RedHat Linux RHEL 5. Security Management Server supports Windows Server 2008 R2. IP290. Software Blade Containers Check Point Platforms and Operating Systems Secure Platform Security Management Security Gateway Multi-Domain Security Management   Smart-1 Smart-1 SmartEvent (5.

For Windows 2003 SP1. 2. Dedicated Gateways To install R75. Ultimate Service Pack SP3 SP1 .microsoft.4 kernel 2. You cannot upgrade these dedicated gateways to R75.You can upgrade a DLP-1 9571 to R75. VSX Appliances . 64-bit 2 RHEL 5. do a clean installation of R75.20 installation.0 RedHat RHEL 5.Series 80.18 N/A N/A 32-bit 32-bit Notes 1.20.com/kb/906469). VSX-1 Supported Products Page 12 .IPS-1 Sensor. IPS-1 Sensor.20:   Open Server . but you must first do a BIOS upgrade before installing R75. Enterprise. UTM-1 Edge.6.20 on an R71 DLP-1 appliance or an R71 DLP open server.20 and then do a clean R75.checkpoint. Note . 64-bit 32-bit.Supported Security Products by Platform Operating System Versions The versions of the Microsoft and RedHat operating systems that are listed in the Security Software Containers table are: Operating System Windows XP Windows 2003 Server Microsoft Windows 2008 Server Windows 7 Editions Professional N/A N/A Professional.20. SP2 SP1. SP2 N/A 1 32 or 64-bit 32-bit 32-bit 32-bit. See sk62903 (http://supportcontent. you must install the hotifx specified in Microsoft KB 906469 (http://support. Windows 2008 Server 64-bit is supported for Security Management only.com/solutions?id=sk62903) for details.

On UTM-1 130/270. 7. 4.2 Flashbased         Windows Server 2003 Windows Server 2008 Crossbeam X-series       4           Mobile Access DLP 1 Application Control            Anti-Virus & Anti-Malware URL Filtering 4      Anti-Spam & Email Security Web Security Advanced Networking QOS Advanced Networking Dynamic Routing and Multicast Support Acceleration & Clustering                2  2  3 Notes about Security Gateway Software Blades 1. 2. including Full HA. Firefox 3. Only third-party clustering is supported on Crossbeam.2 Diskbased Firewall Identity Awareness IPSec VPN IPS 4 Microsoft IPSO 6. or with Firewall and Security Management software blades. Acceleration is not supported. DLP supports High-Availability clusters. DLP supports Load Sharing clusters in the Detect mode. you can use DLP with Firewall and other Security Gateway software blades. Chrome 8. Supported Products Page 13 . 3. HTTPS Inspection is supported only on SecurePlatform and IPSO. 8.4.Supported Security Products by Platform Security Gateway Software Blades Software Blade Operating System Check Point Secure IPSO Platform 6. 9. The DLP portal supports these web browsers: Internet Explorer 6. and Safari 5. Only Clustering is supported on Windows.

Ultra5.Supported Security Products by Platform Security Management Software Blades Software Blade Operating System Check Point Secure Platform IPSO 6.0. 7 RedHat Solaris Linux RHEL 5. Supported Products Page 14 .5 .2 Diskbased  Microsoft Windows Server 2003                   ** Windows Server 2008  Windows XP. and Firefox 1.0 ** SmartEvent is supported on 32-bit only.4 SPARC Network Policy Management Endpoint Policy Management Logging & Status Monitoring SmartProvisioning Management Portal* User Directory SmartWorkflow SmartEvent SmartReporter                                      * Management Portal is supported on the following Web browsers: Internet Explorer 7.3.

Clients and Consoles by Windows Platform Clients and Consoles by Windows Platform Check Point Product XP Home (SP3) 32-bit      XP Pro (SP3) 32-bit                Server 2003 (SP1-2) 32-bit   Server 2008 (SP1-2) 32-bit  1 Vista Vista Windows 7 (SP1) (SP1) Ultimate & 32-bit 64-bit Enterprise 32-bit             2 Windows 7 Ultimate & Enterprise 64-bit  2 SmartConsole SmartDomain Manager SecureClient Endpoint Security VPN SSL Network Extender DLP User Check DLP Exchange Agent Identity Agent      3    3 3 3    3    3 Notes about Clients and Consoles 1.20 supports upgrading from lower software versions and management of lower Security Gateway versions. 3. SSL Network Extender. SmartConsole supports Windows 7 Professional (32 and 64 bit). Upgrade Paths and Interoperability R75.20 Security Gateways support Abra Secure Portable Workspace R70.10 Supported Products Page 15 . R70 is not supported. and Identity Agent clients support all editions of Windows 7.20:    R71. SmartConsole supports Windows Server 2008 R2. Supported Management and Gateway Upgrade Paths You can upgrade these Security Management Server and Security Gateway versions to R75. Abra Secure Portable Workspace R75.1 only. Endpoint Security VPN. 2.30 R75 R75.

1.UTM-1 Edge and Safe@ devices that use locally configured VPN connections with download configuration settings. To install R75. R75.com/solutions?id=sk64361).20 with an ISO file when WebUI is not possible. R70.20.5. R70. R70. Run: mount –o loop /var/tmp/<name>. R70. 2. To enable this configuration with R75.0 Version DLP-1 IPS-1 Series 80 VSX Connectra UTM-1 Edge GX Endpoint Clients SecureClient Endpoint Connect Endpoint Security up to SecureClient NGX R60 HFA 3 with support for Windows 7 32-bit up to Endpoint Security VPN R75 for Windows up to R73 HFA1 *.Upgrade Paths and Interoperability Compatibility with Gateways and Endpoint Clients Release Gateways Security Gateway NGX R65. R71. Download the applicable ISO file from the R75.10.iso /cdrom 4.com/documentation_download?ID=10327) Upgrade Package via CLI You can use these command line instructions to install R75. R71. may experience VPN connectivity failure with R75. To upgrade pre-R71 IPS-1 Sensors.20 Home Page (http://supportcontent.20 Security Gateways. Copy the ISO file to /var/tmp.40. do a clean install of R71 IPS-1 Sensor software on the IPS-1 Sensor. IPS-1 Upgrade Paths and Interoperability R75 Security Management servers can only manage R71 IPS-1 Sensors. R71.20.checkpoint.30. Run: patch add cd Supported Products Page 16 .checkpoint. (http://supportcontent.10 R71 and higher R71 R71 VSX NGX R65.20. R70. R71. 3.20 using the CLI: 1.30.checkpoint.x and above * 4. VSX NGX R67 Centrally Managed NGX R66 7.com/solutions?id=sk65369). R75. see sk65369 (http://supportcontent.

20 is supported on IPSO flash-based models:         IP290 IP390 IP560 Advanced Routing and SecureXL are included by default. Note .html) before installing SecurePlatform on the target hardware.com/services/techsupport/hcl/index. including open servers and network interface cards.SecurePlatform Platform Requirements In This Section SecurePlatform IPSO Linux Microsoft Windows Solaris Maximum Number of Interfaces Supported by Platform 17 17 18 18 19 20 SecurePlatform This release is shipped with the latest SecurePlatform operating system. R75. IPSO  Only clean installation of R75. Note . See the list of certified hardware (http://www.checkpoint.20 on IPSO flash-based models requires 2GB RAM. Linux. and Hybrid) are supported. You cannot manage UTM-1 Edge devices from a Security Management server on an IPSO platform. Clustering on IPSO supports VRRP and IP Clustering. which supports a variety of hardware. Linux. Flash-based. All currently available IPSO platform types (Disk-based. It is not supported with Windows and non-Windows platforms (SecurePlatform. or Solaris. and Solaris).This is more required disk space than that required by earlier versions. Platform Requirements Page 17 .Cross-platform High Availability is supported if all of the platforms are SecurePlatform.

3.2. Linux. Disable SeLinux. and Solaris).1-2 package.i386.Cross-platform High Availability is supported if all of the platforms are SecurePlatform.1-2 package installed by running: rpm -qa | grep sharutils-4. and Solaris).2. Microsoft Windows Note . 2. a) Make sure that SeLinux is disabled by running: getenforce b) If SeLinux is enabled. Install the compat-libstdc++-33-3.3-61. disable it by setting SELINUX=disabled in the /etc/selinux/config file and rebooting the computer.6.i386. Platform Requirements Page 18 . It is not supported with Windows and non-Windows platforms (SecurePlatform.Cross-platform High Availability is supported if all of the platforms are SecurePlatform. Linux.1-2.6.6.1-2 b) If the package is not already installed. Install the sharutils-4.3-61 package by running: rpm –qa | grep compat-libstdc++-33-3. a) Make sure that you have the sharutils-4. or Solaris.rpm This package can be found on CD 3 of RHEL 5. or Solaris. a) Make sure that you have the compat-libstdc++-33-3.Linux Linux Note .2.rpm This package can be found on CD 2 of RHEL 5. Linux. install it by running: rpm –i compat-libstdc++-33-3. High Availability Legacy mode is not supported on Windows. Linux. It is not supported with Windows and non-Windows platforms (SecurePlatform. Before you install Security Management on Red Hat Enterprise Linux 5: 1. install it by running: rpm –i sharutils-4.3-61 package.3-61 b) If the package is not already installed.6.2.

Required Packages      SUNWlibC SUNWlibCx (except Solaris 10) SUNWter SUNWadmc SUNWadmfw Required Patches The patches listed below are required to run Check Point software on Solaris platforms. To display your current patch level. Required only for 32 bit systems Required only for 64 bit systems Note . Linux. remove 113652-01. Linux.Solaris Solaris Security Management Server and Multi-Domain Security Management are supported with Solaris running on UltraSPARC 64-bit platforms. It is not supported with Windows and non-Windows platforms (SecurePlatform.Cross-platform High Availability is supported if all of the platforms are SecurePlatform. Multi-Domain Security Management is not supported on Sun TSeries servers.com (http://sunsolve. 110380-03 109147-18 109326-07 108434-01 108435-01 109147-40 or higher Solaris 9 112233-12 112902-07 116561-03 Only if dmfe(7D) Ethernet driver is defined on the machine 112963-25 or higher Solaris 10 117461-08 or higher We recommend that you install MultiDomain Security Management on Sun MSeries servers. use the command: showrev -p | grep <patch number> Platform Solaris 8 Required 108528-18 Recommended Notes If the patches 108528-17 and 113652-01 are installed.sun.com). They can be downloaded from: http://sunsolve. and then install 108528-18. Platform Requirements Page 19 . or Solaris.sun. See Management Products by Platform ("Supported Security Products by Platform" on page 11). and Solaris).

200 virtual interfaces per physical interface are supported. Platform SecurePlatfor m Max Number of Interfaces 1015 Notes 1. IPSO Windows 1024 32 Platform Requirements Page 20 .Maximum Number of Interfaces Supported by Platform Maximum Number of Interfaces Supported by Platform The maximum number of interfaces supported (physical and virtual) is shown by platform in this table. SecurePlatform supports 255 virtual interfaces per physical interface. When using Dynamic Routing on SecurePlatform. 2.

com/documentation_download?ID=11547).com/dc/download.Security Gateway Hardware Requirements Minimum System Requirements In This Section Security Gateway Hardware Requirements Security Management Hardware Requirements SmartConsole and SmartDomain Manager Hardware Requirements Multi-Domain Security Management Requirements SmartEvent Requirements SmartReporter Requirements Performance Pack For SecureClient Requirements. 21 22 22 23 23 24 24 Security Gateway Hardware Requirements For open servers: Component Processor Windows Intel Pentium IV or 1.htm?ID=8371).checkpoint. see the SecureClient NGX R66 Release Notes (http://downloads.4GB 512MB Yes One or more supported One or more cards Minimum System Requirements Page 21 .checkpoint. For Endpoint Security Server and Client requirements. see the Endpoint Security R73 HFA1 Release Notes (http://supportcontent.5 GHz equivalent Free Disk Space Memory Optical Drive Network Adapter 1GB 512MB Yes One or more SecurePlatform on Open Servers Intel Pentium IV or 2 GHz equivalent 10GB 512MB Yes Linux Intel Pentium IV or 2 GHz equivalent 1.

SecureClient Packaging Tool. SmartProvisioning.Security Management Hardware Requirements Security Management Hardware Requirements For open servers: Component Processor Windows Intel Pentium Processor E2140 or 2 GHz equivalent processor 1GB Linux SecurePlatform on Open Servers Solaris Intel Pentium Intel Pentium Processor Sun Processor E2140 E2140 or 2 GHz UltraSPARC IV or 2 GHz equivalent processor and higher equivalent processor 1. SmartView Monitor. SmartUpdate. including: SmartDashboard. SmartView Tracker.4GB 10GB (installation includes OS) 1GB Yes (bootable) One or more 1GB Free Disk Space Memory Optical Drive Network Adapter 1GB Yes One or more 1GB Yes One or more 512MB Yes One or more SmartConsole and SmartDomain Manager Hardware Requirements This table shows the minimum hardware requirements for console applications. and SmartDomain Manager. Component CPU Memory Disk Space Optical Drive Video Adapter Windows Intel Pentium Processor E2140 or 2 GHz equivalent processor 512MB 500MB Yes minimum resolution: 1024 x 768 Minimum System Requirements Page 22 . and SmartEvent. SmartReporter.

Multi-Domain Security Management Requirements Multi-Domain Security Management Requirements The minimum recommended system requirements for Multi-Domain Security Management are: Component CPU Linux Solaris SecurePlatform Intel Pentium Processor E2140 or 2 GHz equivalent processor 4GB 10GB (install includes OS) Yes (bootable) Intel Pentium Processor UltraSPARC III E2140 or 2 GHz 900MHz equivalent processor 4GB 2GB 4GB 2GB Memory Disk Space Optical Drive Yes Yes Multi-Domain Security Management Resource Consumption Resource consumption is dependent on the scale of your deployment. The Multi-Domain Security Management disk space requirements are:   For basic Multi-Domain Server installations: 2GB (1GB /opt. the more disk space. and a large buffer size. memory. For each Domain Management Server: 400MB (for the Domain Management Server directory located in /var/opt) SmartEvent Requirements You can install SmartEvent on a Security Management Server or on a different.8 GHz 4GB 25GB SmartEvent is not supported on Solaris platforms. 1GB /var/opt). To optimize SmartEvent performance:   Use a disk available high RPM. and CPU are required. The larger the deployment. dedicated computer. Increase the server memory. Minimum System Requirements Page 23 . Component CPU Memory Disk Space Windows/Linux/SecurePlatform Intel Pentium IV 2.

40GB for temp directory) Yes 80MB 60GB (40GB for database. Configure the network connection between the SmartReporter server and the Security Management server to the optimal speed. For deployments that monitor fewer logs. This can increase consolidation performance to as much as 32GB of logs for each day. 20GB for temp directory) Yes 80MB 100GB (60GB for database. Check Point appliances with this configuration:        Power-1 11000 Series Examples of open servers with these configurations: HP ProLiant DL-360 G6 HP ProLiant DL-380 G6 Dell PowerEdge R610 Dell PowerEdge R710 IBM System x3550 M2 IBM System x3650 M2 Minimum System Requirements Page 24 . 20GB for temp directory) Yes Solaris UltraSPARC III 900 MHz 1GB DVD Drive Optimizing SmartReporter Performance We recommend these tips to optimize SmartReporter performance:      Disable DNS resolution. Performance Pack The recommended platform configuration for Performance Pack a computer with a Quad-Core Intel Xeon Processor 5xxx with 6GB RAM. Use UpdateMySQLConfig to adjust the database configuration and adjust the consolidation memory buffers to use the more memory.0 GHz 2GB (on 2 physical disks) 80MB 60GB (40GB for database. Component CPU Memory Disk Space Installation: Database: Windows & Linux Minimum Intel Pentium IV 2. Increase memory for better performance. or more. SmartReporter can be installed on a Security Management Server or on a dedicated machine. you can use a computer with less CPU or memory. Install a disk with high RPM (revolutions per minute) and a large buffer size.SmartReporter Requirements SmartReporter Requirements These hardware requirements are for a SmartReporter server that monitors at least 15GB of logs each day and generates many reports.0 GHz 1GB Windows & Linux Recommended Dual CPU 3.

. Run: ...Done! Uninstalling R75 Compatibility Package package.. Uninstalling Page 25 .Done! Uninstalling Security Gateway / Security Management package.. 1....Done! Uninstalling Management Portal package. Do you want to continue (y/n) ? y Stopping Check Point Processes. Use these procedures to install R75.Done! Uninstalling Connectra R66 Compatibility Package package.Done! Uninstalling CPSG 80 Series compatibility package package...This uninstall procedure does not remove Endpoint Security or Multi-Domain Security Management Products..Done! Uninstalling V40 Compatibility Package package. Uninstallation program is about to stop all Check Point processes.Done! Uninstalling NGX Compatibility Package package.Done! Uninstalling UTM-1 Edge compatibility Package package.20 2. At the prompt.Done! Uninstalling R71 Compatibility Package package.... Change directory to: /opt/CPUninstall/R75.Done! Uninstalling Mobile Access package..20 packages will be uninstalled..Done! Uninstalling Performance Pack package../UnixUninstallScript Example of Uninstall output: *********************************************************** Welcome to Check Point R75..Done! Uninstalling SmartEvent and SmartReporter Suite package.20.20 Uninstall Utility *********************************************************** All R75. Do you wish to reboot your machine (y/n) ? n If any package fails to uninstall.Done! Uninstalling CPinfo package.. Open Start > Check Point > Uninstall R75.20/ 2.Done! Package Name Status ----------------Mobile Access Succeeded Management Portal Succeeded SmartEvent and SmartReporter Suite Succeeded Performance Pack Succeeded R75 Compatibility Package Succeeded R71 Compatibility Package Succeeded CPSG 80 Series compatibility package Succeeded Connectra R66 Compatibility Package Succeeded NGX Compatibility Package Succeeded V40 Compatibility Package Succeeded UTM-1 Edge compatibility Package Succeeded CPinfo Succeeded Security Gateway / Security Management Succeeded ***************************************************** Uninstallation program completed successfully.....Performance Pack Uninstalling Important .... the script generates a log file and prints its location on the screen. enter Y to continue.. Platform Windows Linux IPSO Solaris Procedure 1..

Sign up to vote on this title
UsefulNot useful