> Source: [sk181988](https://support.checkpoint.com/results/sk/sk181988)

# sk181988 - IoT Protect in Locally Managed Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk181988 |
| Date Created | 2024-02-04 |
| Last Modified | 2025-02-27 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1900, 2000, 1600, 1800 |

## Solution

Introduction
------------

Quantum Spark IoT Protect secures your network's Internet of Things (IoT) assets from cyber-attacks. This feature protects only the IoT assets (for example, IP cameras, Smart TVs, printers, etc.) that are discoverable and managed by the Security Gateway. The feature is enabled by default on the Quantum Spark Gateway to discover the IoT assets in your network and get the relevant security rules to enforce the security policies for these IoT assets.

For more information, see the [R81.10.X Locally Managed Guide for the 1500, 1600, 1800, 1900 and 2000 Appliance Series](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Default.htm).

Requirements
------------

The following general requirements must be met:  

Check Point Appliances:

* Supported on 15XX,1600, 1800, 1900 or 2000 models running the R81.10.10 code base.  

  **Important:**
  * Industrial gateways are not supported.

  * IoT functionality is not supported on 1595R appliances when managed locally. As a result, the IoT configuration page does not appear in the WebUI for these devices. To enable IoT features, you must update the appliance license accordingly.

* Internet connection

* License: SNBT

Overview
--------

When you integrate Quantum Spark IoT Protect with your Check Point Quantum Security Gateway, it automatically creates the profiles necessary to discover IoT assets connected to the Security Gateway. During the integration, the Security Gateway collects information on the connected assets. The information is sent to cloud services that return the type of the asset and the relevant security policy.

Getting Started
---------------

From the R81.10.10 release, the IoT Protect feature is enabled by default. After upgrade to R81.10.10 (or higher), the IoT policy will be automatically applied on the connected assets.

You can manage the IoT policy in these ways:

* For an IoT device type in WebUI \> **Access Policy** view \> **Firewall** section \> **IoT** page.
* For each single IoT asset in WebUI \> **Logs and Monitoring** view \> **Status** section \> **Assets** page.  
  The **Assets** page shows the devices that were connected during the last 24 hours.

Monitoring and Controlling IoT
------------------------------

### WebUI \> "Access Policy" view \> "Firewall" section \> "IoT" page

Quantum Spark IoT Protect has a WebUI page dedicated to managing policies for different types of IoT devices.

For example, you might have various categories of IoT devices like smart cameras, thermostats, and motion sensors. On the IoT page, you can define and adjust the security policies for each of these categories separately.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1707043673569/iot1202402041253581.png)

* Upper panel (Counter + filter) IoT Assets

  * Counts IoT assets which were connected during the last 24 hours.

  * Manually blocked - Counts IoT assets which were manually blocked. Click on the icon to filter the blocked assets.

  * Infected hosts - Counts IoT assets which are infected. Click on the icon to filter the infected assets.

  * Unauthorized domains - Counts assets that try to access domains which are not included in IoT policy.

  * Unprotected assets - Counts assets that are not protected by IoT policy.

### Settings

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1707043673569/iot2202402041255442.png)

* IoT - Monitor mode. The IoT blade will not drop traffic. Access to an unauthorized domain will be logged and an alert sent to the administrator.

* Update practice now.

* Trusted DNS: Custom - Trust configured DNS servers.

  * Popular -Trust configured DNS servers and popular DNS servers e.g: 8.8.8.8.

  * All - Trust all DNS servers.

  * See the Troubleshooting section for guidance on specific usage cases.

* Newly discovered functions.

  * Always prevent.

  * Always detect.

  * Define IoT mode per asset type.

### Card view

* Each card presents data for a specific device type: IoT policy, assets status

* Right drawer is used to view and edit IoT policy per device type:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1707043673569/iot3202402041257373.png)

* IoT policy Prevent - Blocks traffic to domains which are not part of the IoT policy.

* Monitor - Alerts if an IoT asset tries to access a domain which is not part of the IoT policy.

* Block - Blocks access to the internet.

* Disable - Disables IoT policy for a device type.

<!-- -->

* Policy view - Presents a list of allowed domains per device type and vendor.

* Approve destinations - Option to add an allowed domain per specific device type.

* Links:

  * View all assets of this device type.

  * View unauthorized logs for this device type.

  * View notifications for this device type.

* Enable function's log - Log all traffic for this device type.

### WebUI \> "Logs and Monitoring" view \> "Status" section \> "Assets" page

The **Assets** page offers two different ways to view the list of assets.

The card view groups the assets by its type:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1707043673569/iot4202402041300114.png)

Overview panel (counter + filter)

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1707043673569/iot5202402041300435.png)

**Assets** - Counts assets which were connected during the last 24 hours.

**IoT Assets** - Counts IoT assets which were connected during the last 24 hours (+ unrecognized).

**Infected hosts** - Counts infected asset. Click on the icon to filter the infected assets.

**Manually blocked** - Counts assets which were manually blocked. Click on the icon to filter the blocked assets.

**Unauthorized domains** - Counts assets that try to access domains which are not included in IoT policy.

### Right drawer

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1707043673569/iot6202402041301156.png)

* **IoT Tab** - Asset policy:

  * Prevent - Block traffic to domains which are not part of the IoT policy.

  * Monitor - Alerts if an IoT asset tries to access adomain which is not part of the IoT policy.

  * Block access to the internet.

  * Exclude from IoT - Disable IoT policy for a specific asset.

* **Override Bypass Description** - Add a description for a specific asset.

  * **Override type** - Change the type of a specific asset if it was not recognized or recognized wrongly.

  * **Override vendor** - Change the vendor of a specific asset if it was not recognized or recognized wrongly.

  * **Bypass policy** - Do not run a deep inspection (URL and Application control ) on the asset.

  * **Bypass SSL inspection**.

### Bypass

Bypass an untrusted IoT + device recognition on untrusted network (default Bypass IoT per MAC address (i.e do not run IoT on routers).

Troubleshooting
---------------

**IoT asset tries to access an unauthorized domain.**

Allowing an asset to communicate with a domain that falls outside the scope of the automatically generated IoT policy let it be added to the "Approved Destination" designation. By adding the domain to the approved destination list, you are explicitly permitting the asset to establish a connection with that specific IP address or domain. This allows for flexibility in managing network access for assets in unique situations.

**Handling network devices (routers/Access Points etc.)**

If there is a network device which is connected behind the gateway (i.e. Access Point / router), we recommend that you configure it as a Layer 2 device. By configuring it as an L2 device, you enable the assets behind it to be discovered, recognized and managed by the IoT Blade in Quantum Spark.

**Connectivity issue**

If you experience a connectivity issue please try to change the IoT cleanup rule to "Monitor" and contact us:

Go to:**Access Policy** \> **IoT** \> **Advanced policy settings**

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1707043673569/iot7202402041302167.png)

**DNS**

Sometimes an IoT device uses its own DNS (does not use the gateway as a DNS server). In this case we recommend that you configure the "trustDNS" to **ALL** in the **Access Policy** \> **IoT** \> **Advanced policy settings**.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1707043673569/iot8202402041302478.png)

When a new device type (i.e. the first time the gateway discovers the HP printer) connects to the gateway, it triggers the install policy operation. The purpose of this automated operation is to ensure that the newly connected device complies with the designated IoT policy. By enforcing the new policy, the system takes measures to protect and manage the device according to the established security guidelines.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
