Configuring OPSEC for Check Point Multi-Domain Management (Provider-1)

This method ensures that the IBM QRadar Check Point FireWall-1 DSM accepts Check Point Multi-Domain Management (Provider-1) events by using OPSEC.

About this task

In the Check Point Multi-Domain Management (Provider-1) Management Domain GUI (MDG), create a host object that represents the QRadar. The leapipe is the connection between the Check Point Multi-Domain Management (Provider-1) and QRadar.

To reconfigure the Check Point Multi-Domain Management (Provider-1) SmartCenter (MDG):

Procedure

  1. To create a host object, open the Check Point SmartDashboard user interface and select Manage > Network Objects > New > Node > Host.
  2. Type the Name, IP address, and write comments if needed.
  3. Click OK.
  4. Select Close.
  5. To create the OPSEC connection, select Manage > Servers and OPSEC Applications > New > OPSEC Application Properties.
  6. Type a Name, and write comments if needed.

    The Name that you enter must be different than the name used in Step 2.

  7. From the Host drop-down menu, select the QRadar host object that you created.
  8. From Application Properties, select User Defined as the Vendor type.
  9. From Client Entries, select LEA.
  10. To configure the Secure Internal Communication (SIC) certificate, click Communication and enter an activation key.
  11. Select OK and then Close.
  12. To install the Policy on your firewall, select Policy > Install > OK.