> Source: [sk108437](https://support.checkpoint.com/results/sk/sk108437)

# sk108437 - How to configure the External Security Log Server on Locally Managed SMB appliances

| Property | Value |
|----------|-------|
| Solution ID | sk108437 |
| Date Created | 2015-11-06 |
| Last Modified | 2024-11-26 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 910 |

## Solution

Follow these steps:

1. Connect with SmartDashboard to the Security Management Server / Domain Management Server.
2. Create a new Security Gateway object for the appliance:

   1. In ***Network Objects*** , right-click on ***Check Point*** - go to ***Check Point*** - click on ***Security Gateway/Management...***:

      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1446134118692/Untitled11510290858.png)  

   2. Select ***Wizard Mode***:

      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1446134118692/Untitled21510290858.png)   

   3. On the ***General Properties*** page:

      1. Enter the *Gateway Name **exactly as it is on the Gateway.***
      2. In *Gateway platform* , select "*Other*".
      3. Enter *Gateway IP address.*
      4. Click on *Next.*

      *Example*:
      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1446134118692/Untitled31510290900.png)   

   4. On the ***Trusted Communication*** page, select ***Skip and initiate trusted communication later*** - click on "*Next"*:

      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1446134118692/Untitled41510290900.png)   

   5. Click on "Finish".
   6. Click on "Save" to save the changes (or go to ***File*** menu - click on ***Save***).

      *Example*:
      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1446134118692/Untitled51510290901.png)   

   7. The new Gateway object should appear in *Network Objects*.
3. Open the appliance's object - click on ***Communication...***:

   1. Select platform ***Small Office Appliance***   

   2. Select "*Initiate trusted communication securely by using a one-time password* ".  

   3. Select "*Initiate trusted communication automatically when the Gateway connects to the Security Management server for the first time* ".  

   4. Click on "OK".

   *Example*:
   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1446134118692/Untitled61510290902.png)   

4. Save the changes (go to ***File*** menu - click on ***Save***).
5. Get the Management Server's SIC name:

   1. Connect to the command line on the Security Management Server / Multi-Domain Security Management Server.   

   2. Login to Expert mode.
   3. On the Multi-Domain Security Management Server, switch to the context of the involved Domain Management Server:

      ***\[Expert@HostName:0\]# mdsenv \<Name of Domain Management Server\>***
   4. Get the SIC name:

      ***\[Expert@HostName:0\]# $CPDIR/bin/cpprod_util CPPROD_GetValue SIC MySICname 0***

      Copy the entire string.
      > *Example output*:
      > `cn=cp_mgmt,o=My_MGMT-1..gugcq3`
6. Configure the External Security Log Server in the appliance's WebUI:

   1. Connect to the appliance's WebUI and log in.   

   2. Go to the ***Logs \& Monitoring*** tab - in the left pane, click on ***Log Servers***   

   3. In the "*External Security Log Server - not configured* " line, click on ***Configure...***
   4. Configure the External Security Log Server:

      1. Enter the IP address of the Security Management Server / Domain Management Server.
      2. Enter the Management Server's SIC name.
      3. Enter the SIC password.
      4. Click on ***Apply***.

      *Example*:
      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1446134118692/Untitled81510290905.png)   

   5. A message should appear in SmartDashboard that SIC was established with the appliance.

      *Example*:
      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1446134118692/Untitled91510290905.png)
7. Install database (go to ***File*** menu - click on ***Install database***)

8. Connect with SmartView Tracker to the Security Management Server / Domain Management Server and verify that logs are received from the appliance.

   *Example*:
   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1446134118692/Untitled111510290907.png)

**Troubleshooting:**

If the connection between the Gateway and the Management Server does not succeed, you may get the following error on the Gateway: **Unable to connect to Log Server. Exit Code 1**

What to check:

* Run CPCA debug on the Management Server: **#*fw debug cpca on TDERROR_ALL_ALL=5***;
* Run **#** ***tail -f $FWDIR/log/cpca.elg*** ;
* Try to search for : "...***common name is missing in dn***" that states that the Gateway name/certificate is not the same/invalid.
* Try to fix it by reinitializing the Gateway Internal CA and creating a Gateway object with the same name as the physical Gateway.
* Verify that the Gateway object name is now **identical** to the name that is configured on the physical Gateway.
* Reinitialize the SIC between the locally managed Gateway and the Management Server.
* In Management, check the CPCA debug again and look for "... **cert status is now valid**".
* Turn off the debug: ***fw debug cpca off TDERROR_ALL_ALL=0***;

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
