> Source: [sk168732](https://support.checkpoint.com/results/sk/sk168732)

# sk168732 - How to configure a 3rd party IoT Controller support on a Multi-Domain Security Management Server R80.40

| Property | Value |
|----------|-------|
| Solution ID | sk168732 |
| Date Created | 2020-08-27 |
| Last Modified | 2022-09-05 |
| Technical Level | General |
| Products | Multi-Domain Security Management Server, IoT Security |
| Versions | R82.10, Cloud, R82.x, R81.20, R82, R82.20 |
| OS | Gaia |

## Solution

### Introduction

The complexity of using IoT devices in the modern work environment such as hospitals, industries, and smart-buildings has, at cost, exposed them to ill-natured and harmful cyberattacks. Malicious cyber invasions into IoT devices have caused considerable financial loss to numerous enterprises. In addition to monetary loss and physical damage, these attacks can lead to data breaches, data tampering, ransomware, and even denial of service.

### Configuring a 3rd party IoT Controller on a Multi-Domain Security Management Server R80.40

You can configure the 3rd party IoT Controller on a Multi-Domain Server.

You can configure the IoT Discovery Service in each Domain.

**Note** - Configuring a new IoT controller generates a new IoT policy layer in the selected policies, a new Threat Prevention profile, and a new rule in the Threat Prevention policy.

**Prerequisites:**

1. [Multi-Domain Security Management Server R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736)
2. [R80.40 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm), Take 91 or higher
3. [R80.40 SmartConsole](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40_SC/Default.htm), Build 415 or higher

**Configuration:**

1. Connect with SmartConsole to the applicable Domain.

2. In the top right pane, click **New** \> **More** \> **IoT Discovery Service**.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk168732/new_iot_controller202008261844002.png)
3. Configure the IoT Discovery Service object - on the **General** pane:

   1. In the **top field**, enter the desired object name.

   2. In the **Hostname** field, enter an IP address, hostname, or URL of the 3rd party IoT Controller.

      Supported 3rd party Discovery Engines:
      * Armis
      * Ordr

      Roadmap - add support for these 3rd party Discovery Engines:
      * Claroty
      * Medigate
   3. In the **Port** field, enter the applicable port number you received from the 3rd party IoT Controller.

   4. In the **Pre-shared Key** field, enter the applicable key you received from the 3rd party IoT Controller.

   5. Click **Test Connection**.

   Example:

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk168732/iot_controller202008261842411.png)
4. Configure the IoT Discovery Service object - on the **Gateways** pane:

   Select the Security Gateway to enforce the policy for IoT traffic.
5. Configure the IoT Discovery Service object - on the **Policies** pane:

   Select the policy to apply to the IoT layer.
6. Click **OK**.

7. Publish the SmartConsole session.

8. Install the Access Control Policy and the Threat Prevention Policy on the Security Gateways you selected in the IoT Discovery Service object.

### Known Limitations

* Connectivity from a Multi-Domain Server to the 3rd party IoT Controller through a proxy server is not supported.

### Documentation

* [R80.40 Security Management Administration Guide](https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_SecurityManagement_AdminGuide/Default.htm) \> Chapter "Network Security for IoT Devices".

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
