> Source: [sk180501](https://support.checkpoint.com/results/sk/sk180501)

# sk180501 - How to connect Cloud Firewall Gateways to Smart-1 Cloud

| Property | Value |
|----------|-------|
| Solution ID | sk180501 |
| Date Created | 2023-01-11 |
| Last Modified | 2026-03-29 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R81.10 (EOS), R81.20, R82 |
| OS | Gaia |
| Platform | OpenStack, KVM, AWS, Azure, Alibaba Cloud, Nutanix, GCP, OCI |

## Solution

Introduction
------------

This article describes how to connect a Cloud Firewall (formerly known as CloudGuard) Public Cloud Gateway to Smart-1 Cloud application during the Gateway provisioning process.   
The procedure shows how to create a **Smart-1 Cloud Token** that you paste into the Cloud Firewall provisioning form.  

You can manage the Cloud Firewall Gateways from all types of Security Management servers.  
We recommend the Smart-1 Cloud (Check Point's Management Server as a Service) for managing Cloud Firewall Gateways.   

For more information, refer to [Smart-1 Cloud Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-Guide/Default.htm).  

Prerequisites
-------------

The prerequisites for connecting a Cloud Firewall Gateway to Smart-1 Cloud are:  

* Check Point Portal account
* Enabled Smart-1 Cloud application in the Check Point Portal

If you meet the requirements in the prerequisites, skip to "Connecting a Security Gateway" / "Connecting a Security Cluster" section.  

Supported Configurations
------------------------

These platforms and configurations are supported:  

|-------------|--------------------------------------------------------------|
| Platform    | Supported configurations                                     |
| **Azure**   | Security Gateway, High Availability, VMSS, Virtual WAN, GWLB |
| **AWS**     | Security Gateway, Security Cluster, GWLB                     |
| **GCP**     | Security Gateway, Security Cluster, MIG                      |
| **OCI**     | Security Gateway, Security Cluster                           |
| **Nutanix** | Security Gateway, Security Cluster                           |
| **KVM**     | Security Gateway, Security Cluster                           |
| **Alibaba** | Security Gateway, Security Cluster                           |
| **VMware**  | Security Gateway, Security Cluster                           |
| **Hyper-V** | Security Gateway, Security Cluster                           |

<br />

Create an Check Point Portal account
------------------------------------

Show / Hide this Section   

Check Point Portal is the Check Point cloud platform for hosting the Check Point Security-as-a-Service (SaaS) solutions. For more information, see the [Check Point Portal Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Default.htm).  

1. Visit the [Check Point Portal.](https://portal.checkpoint.com/create-account)
2. Enter your company's name, email address, phone number, and country.
3. Click **Select Data Residency** .  
   The Available Region window opens and shows available services based on region.  
   Click a region's name to see services available for a specific region.  
   A green check mark adjacent to the service name indicates an available service for that region.
4. Select the account type (Customer is the default type). It is possible to change the account type after creating the account.
5. Select these checkboxes:
   * Optional: Subscribe to Check Point Product News.
   * I accept the Infinity Portal terms of service and the Privacy Policy.
6. Follow the activation instructions in the email sent to your account (required before proceeding).
7. To go back to the sign-in page, click Back to sign in and sign in.

Enabling the Smart-1 Cloud Application
--------------------------------------

Show / Hide this Section   

In the Check Point Portal, click the Menu button in the top left corner.

1. From the drop-down menu, select **Smart-1 Cloud**.
2. Accept the service terms and privacy policy and select the box: **I accept the Infinity Portal terms of service and the privacy policy**.
3. Click **Try Now** and then click **Get Started**.
4. Enter the required information to configure the service:
   * Field
   * Description
   * Service Identifier  
     The service identifier you enter is used as a prefix for the unique identifier generated by the application.
   * Desired Log Retention Period  
     The desired retention period to keep the logs.
   * Logs are deleted after the defined period.  
     A notification is sent to your email if the available storage space cannot hold the desired log retention period. When the storage is full, the older logs are deleted.
5. Click **Create**.
6. The Preparing Account window opens.   
   It takes 1-2 minutes to create a new service.   
   After the process is complete, an email is sent to your account.

Connecting a Security Gateway
-----------------------------

Show / Hide this Section   

#### To connect a new Security Gateway: {#Toggle_1}

1. On the left navigation panel of the Smart-1 Cloud portal, click **Gateways \& Servers**.
2. Click the ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180501/new_icon202507241147361.png) (**New)** icon and select **Gateway** .  
   The **Check Point Gateway** window opens.
3. Fill in the required fields for the Check Point Security Gateway:  
   1. **Enter name** - The name for the Security Gateway.
   2. **IP Address:**
      * **Automatic IPv4 address:** Smart-1 Cloud assigns an internal IP address used for cloud communication over an outbound tunnel.
      * **Custom IPv4 address:** Assign a static IP address, except when configuring an SD-WAN Gateway.

      **Note** - We recommend using a static IP address when available. This simplifies configuration for features such as UserCheck, NAT rules, and VPN configuration.

      You can configure the Security Gateway object in Smart-1 Cloud with a static IP address as the primary IP address. This configuration is similar to setting up a Security Gateway from an on-premises Security Management Server.

      When the Security Gateway is configured with a Tunnel IP address, management traffic, control connections, and Smart-1 Cloud tenant communications use this main static IP address through the `maas_tunnel` interface.

      **Important** - For a new Cloud Firewall (Public Cloud) deployment, configure the Security Gateway object in Smart-1 Cloud with a static IP address. Use the IP address from the Security Gateway's `eth0` interface in the **Custom IPv4 address** field.
4. In the **Device** section, click **Connect** .   
   The **Connect Device**window opens.
5. In the Security Gateway section, select **Appliance/Open Server**.
6. Connect to the CLI on the Security Gateway. In Clish, run the provided command to set the authentication token. The initial connection status is **Pending connection** . After the Security Gateway connects to Smart-1 Cloud, the status changes to **Connected**.
7. To establish Secure Internal Communication (SIC) between the Security Gateway and Smart-1 Cloud, enter the one-time password you set on the Security Gateway.
8. Click **Next** and wait until the Security Gateway connection process finishes. Then close the **Connect Device**window.
9. Click **OK**.

#### To connect an existing Security Gateway to Smart-1 Cloud:

1. After migration is complete, click **Connect Gateways**.
2. Go to **Gateways \& Servers** , select the gateway you want to connect, and click **Edit** . The **Check Point Gateway** properties window opens.
3. In the **Device** section, click **Connect**.
4. In the **Connect Device** wizard window that opens, under **Security Gateway** , select **Appliance/Open server**.
5. Follow instructions in the wizard for **Connecting your Gateway** :
   1. Open the CLI on the Security Gateway.
   2. In Clish, run the command shown in the wizard to set the authentication token.  
      The gateway status initially shows **Pending connection** . When the gateway connects successfully to Smart-1 Cloud, the status changes to **Connected**.
   3. Click **Next**.
6. Publish the changes.

#### To connect an existing Security Gateway object with a Tunnel IP address:

If you have an existing Security Gateway, follow these steps to change it to a static IP address:

1. Edit the Security Gateway object in SmartConsole:
   1. Open Web SmartConsole or Streamed SmartConsole.
   2. Change the IP address in the Security Gateway object properties to a static IP address.
   3. Click **OK**.
2. To verify SIC communication, open the Security Gateway object again and click **Test Communication** in the **Options**menu.

You may need to reset the connection token if the token has expired or become invalid.

#### To generate a new token, follow these steps:

1. Double-click the Security Gateway which connection token you need to reset.
2. Click **Options** \> **Reset communication**.
3. Select **Reset the connection token**.
4. Click **Yes**.

Connecting a Security Cluster
-----------------------------

Show / Hide this Section  
These instructions apply to new or existing Cloud Firewall Clusters.

#### To connect a new Cloud Firewall Cluster: {#Toggle_2}

1. From the left navigation panel, click **Gateways \& Servers**.
2. Click the ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180501/new_icon202507241147361.png) (**New** ) icon and select **Cluster** .  
   The **Check Point Cluster** window opens.  
   **Note** - Web SmartConsole supports configuration of a Security Gateway/Cluster object for Gaia OS versions R80.10 and higher.
3. Fill in the required fields:
   * **Enter Name**: The Cluster name.
   * **IP address**: The Cluster VIP IP address.
4. Click **Add...** next to **Member ID 1** .  
   The **Check Point Cluster Member** window opens.
   1. Enter the name and IP address of Member ID 1:
      * **Automatic IPv4 address:**Smart-1 Cloud assigns an internal IP address used for cloud communication over an outbound tunnel.
      * **Custom IPv4 address:** Assign a static IP address, **except**when configuring an SD-WAN Gateway.
   2. Click **Connect** below the Secure Internal Communication.  
      The **Connect Device**window opens.
   3. Select **Appliance/Open Server** in the **Cluster Gateway type**.
   4. Copy the **Token**from the Connect Device screen.
5. Click **Add...** next to **Member ID 2** .  
   Follow steps 4.a-4.d again for this member.
6. In the Security Cluster deployment template:
   1. Paste the Tokens you copied from the Smart-1 Cloud portal for each member into the appropriate fields.
   2. Fill in all remaining fields in the template and start the deployment.
   3. When the Cloud Firewall Gateway deployment completes:
      * A tunnel is established between the Security Gateway and the Smart-1 Cloud.
      * The status of the Security Gateway changes to **Pending trust (SIC) establishment**.
7. In SmartConsole or Streamed SmartConsole:  
   Follow the administration guide specific to your deployed solution to configure the Cluster object and Cluster members in SmartConsole.

**Notes:**

* When you enter the Cluster Virtual IP address, do not use IP addresses from these subnets:

*
  * 100.64.x.x
  * 100.70.x.x
  * 100.71.x.x
  * 100.100.x.x
  * 100.101.x.x
* When you add cluster members to the cluster object, use the existing members created in step 1.

<br />

#### To connect an existing cluster:

This step is required after the cluster's migration to Smart-1 Cloud.

1. After migration is complete, click **Connect Gateways**.
2. Go to **Gateways \& Servers** , select the gateway you want to connect, and click **Edit**.
3. In the **Device** section, click **Connect**.
4. In the **Connect Device** wizard window that opens, under **Security Gateway** , select **Appliance/Open server**.
5. Follow instructions in the wizard for Connecting your Gateway:
   1. Open the CLI on the Security Gateway.
   2. In Clish, run the command shown in the wizard to set the authentication token.
   3. The gateway status initially shows **Pending connection** . When the gateway connects successfully to Smart-1 Cloud, the status changes to **Connected**.
6. Click **Next**.
7. Publish the changes.

Troubleshooting
---------------

Show / Hide this Section   

If the deployment finished and the status of the Security Gateway is still "Waiting for connection" do the followings:  

1. It can take a few minutes for the Security Gateway to establish communication with Smart-1 Cloud. To check that the Security Gateway configuration finished:  
   - Connect to the Security Gateway   
   - Open the */var/log/cloud_config.log* file and verify it ends with "*cloud_config finished successfully* ".  
   - If the logs ended with errors, [contact Check Point Support.](https://www.checkpoint.com/support-services/contact-support/)  

2. If the Security Gateway configuration finished successfully:
   1. Check the */var/log/cloud_config.log* file for "*Failed to establish MaaS tunnel*" message.
   2. Copy the Token from the "Connect gateway" screen
   3. Paste the Token in the Security Gateway.   

   If issue persists, refer to the Troubleshooting section in the [Quantum Smart-1 Cloud Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-Guide/Default.htm).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
