This method ensures that the IBM
QRadar Check Point FireWall-1
DSM accepts Check Point Multi-Domain Management (Provider-1) events by using OPSEC.
About this task
In the Check Point Multi-Domain Management (Provider-1) Management Domain GUI (MDG), create a
host object that represents the QRadar. The leapipe
is the connection between the Check Point Multi-Domain Management (Provider-1) and QRadar.
To reconfigure the Check Point Multi-Domain Management (Provider-1) SmartCenter (MDG):
Procedure
-
To create a host object, open the Check Point SmartDashboard user interface and
select .
-
Type the Name, IP address, and write comments if needed.
-
Click OK.
-
Select Close.
-
To create the OPSEC connection, select .
-
Type a Name, and write comments if needed.
The Name that you enter must be different than the name used in Step 2.
-
From the Host drop-down menu, select the QRadar
host object that you created.
-
From Application Properties, select User Defined
as the Vendor type.
-
From Client Entries, select LEA.
-
To configure the Secure Internal Communication (SIC) certificate, click
Communication and enter an activation key.
-
Select OK and then Close.
-
To install the Policy on your firewall, select .