> Source: [sk184397](https://support.checkpoint.com/results/sk/sk184397)

# sk184397 - How to complete the initial configuration when establishing SIC and fetching policy from a Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk184397 |
| Date Created | 2025-12-18 |
| Last Modified | 2026-08-17 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server, Smart-1 Cloud |
| Versions | R82.10, R82, R81.20, R82.10, Cloud, R82.x, R82.20, R82.x, R81.20, R82, R82.20 |
| OS | Gaia |

## Solution

**This article is for Management Servers that run the versions R82.20 and higher.**

**Table of Contents:**

* (1) Overview
* (2) Configuration Procedure for Security Gateways with a Static IP Address
  * Workflow #1
  * Workflow #2
* (3) Configuration Procedure for Security Gateways with a Dynamic IP Address (DAIP)
* (4) Limitations

<br />

Click Here to Show the Entire Article

(1) Overview {#TOC01}
---------------------

This SecureKnowledge article explains how to establish Secure Internal Communication (SIC) after initially creating a Security Gateway object on the Management Server. This workflow is commonly used when the Security Gateway is not yet accessible during initial configuration, such as during staging or deployment to a remote site.

In this scenario, the administrator first prepares the Security Gateway object on the Security Management Server, Domain Management Server, or Smart-1 Cloud. The actual SIC establishment is then completed later, directly from the Security Gateway.

When SIC is established at a later time, the Security Management Server generates a Certificate Revocation List (CRL) that the Security Gateway must retrieve as part of the SIC process. This CRL is available only for a limited time window (by default, **30 days**). If the Security Gateway does not complete SIC establishment within this period, the process fails and must be re-initiated.

(2) Configuration Procedure for Security Gateways with a Static IP Address {#TOC02}
-----------------------------------------------------------------------------------

Use one of the available workflows that fits your environment better:

* **Workflow #1:**

  1. Part 1 - Preparation on the Management Server

     > Show / Hide this section  
     > 1. Connect with Desktop SmartConsole or Web SmartConsole to the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
     >
     > 2. From the left navigation panel, click **Gateways \& Servers**.
     >
     > 3. Double-click the Security Gateway object.
     >
     > 4. In the left panel, click the **General Properties** page.
     >
     > 5. Open the **Trusted Communication** settings:
     >
     >    * In Desktop SmartConsole:
     >
     >      In the **Machine** section, click **Communication**.
     >    * In Web SmartConsole:
     >
     >      In the **Device** section, click **Connect**.
     > 6. In the opened dialog, select **Prepare the object now, connect from the device later**.
     >
     > 7. Enter a one-time-password.  
     >    **Warning** - Keep this one-time-password secured!
     >
     > 8. Click **OK** to close the **Trusted Communication** window.
     >
     > 9. Click **OK** to close the Security Gateway object.
     >
     > 10. Publish the session.

     {#Workflow1_Static_IP_Address_part_1}
  {#Workflow1_Static_IP_Address_part_1}
  2. Part 2 - Completing the SIC Establishment from the Security Gateway

     > Show / Hide this section  
     > **Important** - When SIC establishment is completed at a later time, the Security Management Server generates a Certificate Revocation List (CRL) that the Security Gateway must retrieve during the SIC process. This CRL is available only for a limited time. If the Security Gateway does not fetch it within this window, SIC establishment fails and must be re-initiated.
     >
     > The Security Gateway can pull this CRL only within the configured fetch window.
     >
     > The default fetch window is **30 days**.
     >
     > If the Security Gateway attempts to complete SIC after the fetch window expires, the CRL pull fails. In this scenario, the SIC establishment must be re-initiated from the Security Management Server.
     >
     > **This behavior applies to all supported Security Gateways that complete SIC establishment at a later stage.**
     >
     > To configure the OTP fetch expiration time on the Management Server:
     > 1. Connect to the command line on your Security Management Server / Multi-Domain Security Management Server.
     >
     > 2. On a Multi-Domain Security Management Server, go to the context of the relevant Domain Management Server:
     >
     >    `mdsenv <IP Address of Domain Management Server>`
     > 3. Configure the OTP fetch expiration time:
     >
     >    `cpca_client set_sic_password_expiration [-y <num_of_years>] [-d <num_of_days>] [-h <num_of_hours>] [-m <num_of_minutes>] [-s <num_of_seconds>]`
     >
     >    Example for an OTP fetch expiration time of 30 days and 10 minutes:
     >
     >    `cpca_client set_sic_password_expiration -d 30 -m 10`
     > 4. Verify the current OTP fetch expiration window:
     >
     >    `cpca_client show_sic_password_expiration`
     >
     > Follow these steps on the Security Gateway to complete the SIC establishment:
     > * **On Check Point Firewalls R82.20 and higher:**
     >
     >   Show / Hide this section  
     >   1. Connect to Gaia Portal on the Security Gateway.
     >
     >   2. In the left panel, navigate to the **System Management** section \> the **Security Management** page.
     >
     >   3. Click **Connect to the Security Management Server now**.
     >
     >   4. Enter the one-time password you entered in SmartConsole in the Security Gateway object.
     >
     >   5. Enter the IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
     >
     >   6. Click **Connect**.
     >
     > * **On Check Point Firewalls R82.10 and lower:**
     >
     >   Show / Hide this section  
     >   In these versions, the procedure is supported only for Security Gateways with a Dynamically Assigned IP Address (DAIP).
     >   1. Connect to the command line on the Security Gateway.
     >
     >   2. Log in to Gaia Clish or the Expert mode.
     >
     >   3. Run:
     >
     >      |----------------------------------------------------------------------------------------------------------------------------------------------------------------|
     >      | `cp_conf sic cert_pull <IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server> <Name of the Security Gateway Object>` |
     >
     >      Example:  
     >      `cp_conf sic cert_pull 192.168.3.57 MySecurityGateway1`
     > * **On Spark Firewalls:**
     >
     >   Show / Hide this section  
     >   See [R82.00.X Spark Firewall Appliances Centrally Managed Administration Guide](https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_R82.00.X/AdminGuides_Centrally_Managed/EN/Content/Topics/First-Time-Deployment-Options.htm) \> Chapter "First Time Deployment Options" \> links to the Getting Started Guide for your appliance model.
     >   1. Connect to WebUI on the Spark Firewall.
     >
     >   2. On the **Security Policy Management** page, select **Central management**.
     >
     >   3. Select **Connect to the Security Management Server now**.
     >
     >   4. On the **Security Management Server Authentication** page:
     >
     >      1. Select **Initiate trusted communication securely by using a one-time password**.
     >
     >      2. Enter the one-time password you entered in SmartConsole in the Security Gateway object.
     >
     >   5. On the **Security Management Server Connection** page:
     >
     >      1. Select **Connect to the Security Management Server now**.
     >
     >      2. Enter the IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
     >
     >      3. Click **Connect**.

     {#Workflow1_Static_IP_Address_part_2}
  {#Workflow1_Static_IP_Address_part_2}
  3. Part 3 - Completing the configuration of the Security Gateway object on the Management Server

     At this stage, SIC was already established with the Security Gateway.

     You can fetch the object settings and the interfaces automatically.
     > Show / Hide this section  
     > **Important** - The Management Server does not automatically update the device attributes and the interfaces in the Security Gateway object. You must complete the configuration of the device attributes and of the interfaces before you install the Security Policy on the Security Gateway object.
     >
     > **Warning** - In Smart-1 Cloud, installing policy before completing the configuration of the interfaces may result in a loss of connectivity with the Security Gateway.
     > 1. Connect with Desktop SmartConsole or Web SmartConsole to the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
     >
     > 2. From the left navigation panel, click **Gateways \& Servers**.
     >
     > 3. Double-click the Security Gateway object.
     >
     > 4. Fetch and examine the device attributes:
     >
     >    1. In the left panel, click the **General Properties** page.
     >
     >    2. Fetch the device attributes:
     >
     >       * In Desktop SmartConsole:
     >
     >         In the **Platform** section, click **Get**.
     >       * In Web SmartConsole:
     >
     >         In the **Device** section, click **Options** \> **Refresh device attributes**.
     > 5. Configure the interface settings:
     >
     >    You can configure the required interface settings in **one** of these ways:
     >    * Fetch the interface settings from the Security Gateway after you establish a SIC trust with it:
     >
     >      1. In the left panel of the Security Gateway object:
     >
     >         * In Desktop SmartConsole:
     >
     >           * In the object of a Check Point Firewall / Cluster:
     >
     >             Click the **Network Management** page.
     >           * In the object of a Spark Firewall / Cluster:
     >
     >             Click the **Topology** page.
     >         * In Web SmartConsole:
     >
     >           Expand **Network Management** and click the **General** page.
     >      2. Write down all current settings for each interface (including its Topology settings).
     >
     >      3. Click **Get Interfaces** \> **Get Interfaces With Topology**.
     >
     >      4. Examine the interface settings.
     >
     >      5. Click **Accept**.
     >
     >      6. If needed, configure the required interface settings.
     >
     >    * Manually configure the required interface settings:
     >
     >      1. In the left panel of the Security Gateway object:
     >
     >         * In Desktop SmartConsole:
     >
     >           * In the object of a Check Point Firewall / Cluster:
     >
     >             Click the **Network Management** page.
     >           * In the object of a Spark Firewall / Cluster:
     >
     >             Click the **Topology** page.
     >         * In Web SmartConsole:
     >
     >           Expand **Network Management** and click the **General** page.
     >      2. From the toolbar, click **Actions** \> **New Interface** to add the required interfaces and configure their settings.
     >
     > 6. Click **OK** to close the Security Gateway object.
     >
     > 7. Install the Access Control Policy on the Security Gateway object.
     >
     > 8. If required in your environment: Install the Threat Prevention Policy on the Security Gateway object.

     {#Workflow1_Static_IP_Address_part_3}
  {#Workflow1_Static_IP_Address_part_3} {#TOC02_Workflow1}
{#TOC02_Workflow1}
* **Workflow #2:**

  1. Part 1 - Preparation on the Management Server

     > Show / Hide this section  
     > 1. Connect with Desktop SmartConsole or Web SmartConsole to the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
     >
     > 2. From the left navigation panel, click **Gateways \& Servers**.
     >
     > 3. Double-click the Security Gateway object.
     >
     > 4. In the left panel, click the **General Properties** page.
     >
     > 5. Open the **Trusted Communication** settings:
     >
     >    * In Desktop SmartConsole:
     >
     >      In the **Machine** section, click **Communication**.
     >    * In Web SmartConsole:
     >
     >      In the **Device** section, click **Connect**.
     > 6. In the opened dialog, select **Prepare the object now, connect from the device later**.
     >
     > 7. Enter a one-time-password.  
     >    **Warning** - Keep this one-time-password secured!
     >
     > 8. Click **OK** to close the **Trusted Communication** window.
     >
     > 9. Click **OK** to close the Security Gateway object.
     >
     > 10. Publish the session.

     {#Workflow2_Static_IP_Address_part_1}
  {#Workflow2_Static_IP_Address_part_1}
  2. Part 3 - Completing the configuration of the Security Gateway object on the Management Server

     At this stage, SIC is not yet established with the Security Gateway.

     You must configure the object settings and the interfaces manually.
     > Show / Hide this section  
     > **Important** - You must complete the manual configuration of the device attributes and of the interfaces before you install the Security Policy on the Security Gateway object.
     >
     > **Warning** - In Smart-1 Cloud, installing policy before completing the configuration of the interfaces may result in a loss of connectivity with the Security Gateway.
     > 1. Connect with Desktop SmartConsole or Web SmartConsole to the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
     >
     > 2. From the left navigation panel, click **Gateways \& Servers**.
     >
     > 3. Double-click the Security Gateway object.
     >
     > 4. Configure the device attributes:
     >
     >    1. In the left panel, click the **General Properties** page.
     >
     >    2. Configure the device attributes:
     >
     >       * In Desktop SmartConsole:
     >
     >         In the **Platform** section, select the correct **Hardware** , **Version** , and **OS**.
     >       * In Web SmartConsole:
     >
     >         In the **Device** section, select the correct **Version** , **Platform** , and **OS**.
     > 5. Configure the required interfaces and their settings:
     >
     >    1. In the left panel of the Security Gateway object:
     >
     >       * In Desktop SmartConsole:
     >
     >         * In the object of a Check Point Firewall / Cluster:
     >
     >           Click the **Network Management** page.
     >         * In the object of a Spark Firewall / Cluster:
     >
     >           Click the **Topology** page.
     >       * In Web SmartConsole:
     >
     >         Expand **Network Management** and click the **General** page.
     >    2. From the toolbar, click **Actions** \> **New Interface** to add the required interfaces and configure their settings.
     >
     > 6. Configure the policy fetch settings:
     >
     >    1. In the left panel, click the **Fetch Policy** page.
     >
     >    2. Select **During policy installation, the policy will not be pushed to the Gateway - the Gateway should fetch the policy**.
     >
     > 7. Click **OK** to close the Security Gateway object.
     >
     > 8. Install the Access Control Policy on the Security Gateway object.
     >
     > 9. If required in your environment: Install the Threat Prevention Policy on the Security Gateway object.

     {#Workflow2_Static_IP_Address_part_2}
  {#Workflow2_Static_IP_Address_part_2}
  3. Part 2 - Completing the SIC Establishment from the Security Gateway

     > Show / Hide this section  
     > **Important** - When SIC establishment is completed at a later time, the Security Management Server generates a Certificate Revocation List (CRL) that the Security Gateway must retrieve during the SIC process. This CRL is available only for a limited time. If the Security Gateway does not fetch it within this window, SIC establishment fails and must be re-initiated.
     >
     > The Security Gateway can pull this CRL only within the configured fetch window.
     >
     > The Default fetch window is **30 days**.
     >
     > If the Security Gateway attempts to complete SIC after the fetch window expires, the CRL pull fails. In this scenario, the SIC establishment must be re-initiated from the Security Management Server.
     >
     > **This behavior applies to all supported Security Gateways that complete SIC establishment at a later stage.**
     >
     > To configure the OTP fetch expiration time on the Management Server:
     > 1. Connect to the command line on your Security Management Server / Multi-Domain Security Management Server.
     >
     > 2. On a Multi-Domain Security Management Server, go to the context of the relevant Domain Management Server:
     >
     >    `mdsenv <IP Address of Domain Management Server>`
     > 3. Configure the OTP fetch expiration time:
     >
     >    `cpca_client set_sic_password_expiration [-y <num_of_years>] [-d <num_of_days>] [-h <num_of_hours>] [-m <num_of_minutes>] [-s <num_of_seconds>]`
     >
     >    Example for an OTP fetch expiration time of 30 days and 10 minutes:
     >
     >    `cpca_client set_sic_password_expiration -d 30 -m 10`
     > 4. Verify the current OTP fetch expiration window:
     >
     >    `cpca_client show_sic_password_expiration`
     >
     > Follow these steps on the Security Gateway to complete the SIC establishment:
     > * **On Check Point Firewalls R82.20 and higher:**
     >
     >   Show / Hide this section  
     >   1. Connect to Gaia Portal on the Security Gateway.
     >
     >   2. In the left panel, navigate to the **System Management** section \> the **Security Management** page.
     >
     >   3. Click **Connect to the Security Management Server now**.
     >
     >   4. Enter the one-time password you entered in SmartConsole in the Security Gateway object.
     >
     >   5. Enter the IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
     >
     >   6. Click **Connect**.
     >
     >   7. Fetch the Security Policy on the Security Gateway:
     >
     >      1. In the **Security Policy** section, select **Download and Install the policy from the Management Server**.
     >      2. Click the **Fetch policy** button.
     >
     >      Note - The **Security Policy** section is disabled, while there is no SIC connection.
     > * **On Check Point Firewalls R82.10 and lower:**
     >
     >   Show / Hide this section  
     >   In these versions, the procedure is supported only for Security Gateways with a Dynamically Assigned IP Address (DAIP).
     >   1. Connect to the command line on the Security Gateway.
     >
     >   2. Log in to Gaia Clish or the Expert mode.
     >
     >   3. Run:
     >
     >      |----------------------------------------------------------------------------------------------------------------------------------------------------------------|
     >      | `cp_conf sic cert_pull <IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server> <Name of the Security Gateway Object>` |
     >
     >      Example:  
     >      `cp_conf sic cert_pull 192.168.3.57 MySecurityGateway1`
     >   4. Fetch the Security Policy on the Security Gateway:
     >
     >      * To fetch the Access Control policy, run:
     >
     >        `fw fetch -f`
     >
     >        By design, it is necessary to install the Access Control policy on a Security Gateway at least one time on the Management Server, before the Security Gateway can fetch it.
     >      * To fetch the Threat Prevention policy, run:
     >
     >        `fw amw fetch -f`
     > * **On Spark Firewalls:**
     >
     >   Show / Hide this section  
     >   See [R82.00.X Spark Firewall Appliances Centrally Managed Administration Guide](https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_R82.00.X/AdminGuides_Centrally_Managed/EN/Content/Topics/First-Time-Deployment-Options.htm) \> Chapter "First Time Deployment Options" \> links to the Getting Started Guide for your appliance model.
     >   1. Connect to WebUI on the Spark Firewall.
     >
     >   2. On the **Security Policy Management** page, select **Central management**.
     >
     >   3. Select **Connect to the Security Management Server now**.
     >
     >   4. On the **Security Management Server Authentication** page:
     >
     >      1. Select **Initiate trusted communication securely by using a one-time password**.
     >
     >      2. Enter the one-time password you entered in SmartConsole in the Security Gateway object.
     >
     >   5. On the **Security Management Server Connection** page:
     >
     >      1. Select **Connect to the Security Management Server now**.
     >
     >      2. Enter the IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
     >
     >      3. Click **Connect**.

     {#Workflow2_Static_IP_Address_part_3}
  {#Workflow2_Static_IP_Address_part_3} {#TOC02_Workflow2}
{#TOC02_Workflow2}

(3) Configuration Procedure for Security Gateways with a Dynamic IP Address (DAIP) {#TOC03}
-------------------------------------------------------------------------------------------

> ### Part 1 - Preparation on the Management Server
>
> > Show / Hide this section  
> > 1. Connect with Desktop SmartConsole or Web SmartConsole to the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
> >
> > 2. From the left navigation panel, click **Gateways \& Servers**.
> >
> > 3. Double-click the Security Gateway object.
> >
> > 4. In the left panel, click the **General Properties** page.
> >
> > 5. Open the **Trusted Communication** settings:
> >
> >    * In Desktop SmartConsole:
> >
> >      In the **Machine** section, click **Communication**.
> >    * In Web SmartConsole:
> >
> >      In the **Device** section, click **Connect**.
> > 6. In the opened dialog, select **Prepare the object now, connect from the device later**.
> >
> > 7. Enter a one-time-password.  
> >    **Warning** - Keep this one-time-password secured!
> >
> > 8. Click **OK** to close the **Trusted Communication** window.
> >
> > 9. Click **OK** to close the Security Gateway object.
> >
> > 10. Publish the session.
>
> ### Part 2 - Completing the SIC Establishment from the Security Gateway
>
> > Show / Hide this section  
> > When working with a DAIP Security Gateway and the SIC establishment is completed from the Security Gateway side, the Security Management Server learns the current IP address of the Security Gateway only after the Security Gateway performs the "Fetch Policy" action for the first time. Until then, the Management Server cannot fetch the device attributes and the interfaces from the Security Gateway.
> >
> > Therefore, you must follow **one** of these workflows:
> >
> > * Complete the configuration on the Management Server, then complete the configuration on the Security Gateway:
> >
> >   Show / Hide this section  
> >   1. Connect with Desktop SmartConsole or Web SmartConsole to the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
> >
> >   2. From the left navigation panel, click **Gateways \& Servers**.
> >
> >   3. Double-click the Security Gateway object.
> >
> >   4. Manually configure the required device attributes:
> >
> >      1. In the left panel, click the **General Properties** page.
> >
> >      2. Configure the required settings:
> >
> >         * In Desktop SmartConsole:
> >
> >           In the **Platform** section, select the correct **Hardware** , **Version** , and **OS**.
> >         * In Web SmartConsole:
> >
> >           In the **Device** section, select the correct **Version** , **Platform** , and **OS**.
> >   5. Manually configure the required interface settings:
> >
> >      1. In the left panel of the Security Gateway object:
> >
> >         * In Desktop SmartConsole:
> >
> >           * In the object of a Check Point Firewall / Cluster:
> >
> >             Click the **Network Management** page.
> >           * In the object of a Spark Firewall / Cluster:
> >
> >             Click the **Topology** page.
> >         * In Web SmartConsole:
> >
> >           Expand **Network Management** and click the **General** page.
> >      2. From the toolbar, click **Actions** \> **New Interface** to add the required interfaces and configure their settings.
> >
> >   6. Configure the Security Gateway to fetch the policy later:
> >
> >      1. In the left panel, click the **Fetch Policy** page.
> >
> >      2. Select the checkbox **During policy installation, the policy will not be pushed to the Gateway - the Gateway should fetch the policy**.
> >
> >   7. Click **OK** to close the Security Gateway object.
> >
> >   8. Install the Access Control Policy on the Security Gateway object.
> >
> >   9. On the Security Gateway, complete the SIC Establishment.
> >
> >      Follow the steps to complete the SIC Establishment from the Security Gateway as described in "Workflow #2 - Step 3: Completing the SIC Establishment from the Security Gateway" (in the procedure "Configuration Procedure for Security Gateways with a Static IP Address").
> >   10. **Optional:** Disable the Security Gateway setting to fetch the policy later:
> >
> >       1. Double-click the Security Gateway object.
> >
> >       2. In the left panel, click the **Fetch Policy** page.
> >
> >       3. Clear **Select During policy installation, the policy will not be pushed to the Gateway - the Gateway should fetch the policy**.
> >
> >       4. Click **OK** to close the Security Gateway object.
> >
> >       5. Install the Access Control Policy on the Security Gateway object.
> >
> >       6. If required in your environment: Install the Threat Prevention Policy on the Security Gateway object.
> >
> >   11. Fetch the Security Policy on the Security Gateway:
> >
> >       * On Check Point Firewalls R82.20 and higher:
> >
> >         1. Connect to Gaia Portal on the Security Gateway.
> >
> >         2. In the left panel, navigate to the **System Management** section \> the **Security Management** page.
> >
> >         3. In the **Security Policy** section, select **Download and Install the policy from the Management Server**.
> >         4. Click the **Fetch policy** button.
> >
> >         Note - The **Security Policy** section is disabled, while there is no SIC connection.
> >       * On Check Point Firewalls R82.10 and lower:
> >
> >         1. Connect to the command line on the Security Gateway.
> >
> >         2. Log in to Gaia Clish or the Expert mode.
> >
> >         3. Run:
> >
> >            |----------------------------------------------------------------------------------------------------------------------------------------------------------------|
> >            | `cp_conf sic cert_pull <IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server> <Name of the Security Gateway Object>` |
> >
> >            Example:  
> >            `cp_conf sic cert_pull 192.168.3.57 MySecurityGateway1`
> >         4. Fetch the Security Policy on the Security Gateway:
> >
> >            * To fetch the Access Control policy, run:
> >
> >              `fw fetch -f`
> >
> >              By design, it is necessary to install the Access Control policy on a Security Gateway at least one time on the Management Server, before the Security Gateway can fetch it.
> >            * To fetch the Threat Prevention policy, run:
> >
> >              `fw amw fetch -f`
> >       * On Spark Firewalls:
> >
> >         1. Connect to the command line on the Spark Firewall.
> >
> >         2. Log in to Gaia Clish or the Expert mode.
> >
> >         3. Run:
> >
> >            |----------------------------------------------------------------------------------------------------------------------------------------------------------------|
> >            | `cp_conf sic cert_pull <IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server> <Name of the Security Gateway Object>` |
> >
> >            Example:  
> >            `cp_conf sic cert_pull 192.168.3.57 MySecurityGateway1`
> >         4. Fetch the Security Policy on the Spark Firewall:
> >
> >            * To fetch the Access Control policy, run:
> >
> >              `fw fetch -f`
> >
> >              By design, it is necessary to install the Access Control policy on a Security Gateway at least one time on the Management Server, before the Security Gateway can fetch it.
> >            * To fetch the Threat Prevention policy, run:
> >
> >              `fw amw fetch -f`
> > * Start with an initial configuration on the Management Server, then complete it after the Security Gateway performs the "Fetch Policy" action:
> >
> >   Show / Hide this section  
> >   1. Connect with Desktop SmartConsole or Web SmartConsole to the Security Management Server / Domain Management Server / Smart-1 Cloud Server.
> >
> >   2. From the left navigation panel, click **Gateways \& Servers**.
> >
> >   3. Double-click the Security Gateway object.
> >
> >   4. Manually configure the required device attributes:
> >
> >      1. In the left panel, click the **General Properties** page.
> >
> >      2. Configure the required settings:
> >
> >         * In Desktop SmartConsole:
> >
> >           In the **Platform** section, select the correct **Hardware** , **Version** , and **OS**.
> >         * In Web SmartConsole:
> >
> >           In the **Device** section, select the correct **Version** , **Platform** , and **OS**.
> >   5. Manually configure one interface with a dynamic IP address:
> >
> >      1. In the left panel of the Security Gateway object:
> >
> >         * In Desktop SmartConsole:
> >
> >           * In the object of a Check Point Firewall / Cluster:
> >
> >             Click the **Network Management** page.
> >           * In the object of a Spark Firewall / Cluster:
> >
> >             Click the **Topology** page.
> >         * In Web SmartConsole:
> >
> >           Expand **Network Management** and click the **General** page.
> >      2. From the toolbar, click **Actions** \> **New Interface** to add one interface with a dynamic IP address and configure the interface settings.
> >
> >   6. Configure the Security Gateway to fetch the policy later:
> >
> >      1. In the left panel, click the **Fetch Policy** page.
> >
> >      2. Select **During policy installation, the policy will not be pushed to the Gateway - the Gateway should fetch the policy**.
> >
> >   7. Click **OK** to close the Security Gateway object.
> >
> >   8. Install the Access Control Policy on the Security Gateway object.
> >
> >   9. If required in your environment: Install the Threat Prevention Policy on the Security Gateway object.
> >
> >   10. On the Security Gateway, complete the SIC Establishment.
> >
> >       Follow the steps to complete the SIC Establishment from the Security Gateway as described in "Workflow #1 - Step 2: Completing the SIC Establishment from the Security Gateway" (in the procedure "Configuration Procedure for Security Gateways with a Static IP Address").
> >   11. In SmartConsole, double-click the Security Gateway object.
> >
> >   12. Fetch the interface settings from the Security Gateway:
> >
> >       1. In the left panel of the Security Gateway object:
> >
> >          * In Desktop SmartConsole:
> >
> >            * In the object of a Check Point Firewall / Cluster:
> >
> >              Click the **Network Management** page.
> >            * In the object of a Spark Firewall / Cluster:
> >
> >              Click the **Topology** page.
> >          * In Web SmartConsole:
> >
> >            Expand **Network Management** and click the **General** page.
> >       2. Write down all current settings for each interface (including its Topology settings).
> >
> >       3. Click **Get Interfaces** \> **Get Interfaces With Topology**.
> >
> >       4. Examine the interface settings.
> >
> >       5. Click **Accept**.
> >
> >       6. If needed, configure the required interface settings.
> >
> >   13. **Optional:** Disable the Security Gateway setting to fetch the policy later:
> >
> >       1. In the left panel, click the **Fetch Policy** page.
> >
> >       2. Clear **During policy installation, the policy will not be pushed to the Gateway - the Gateway should fetch the policy**.
> >
> >   14. Click **OK** to close the Security Gateway object.
> >
> >   15. Install the Access Control Policy on the Security Gateway object (this time with the updated interfaces data).
> >
> >   16. If required in your environment: Install the Threat Prevention Policy on the Security Gateway object.
> >
> >   17. Fetch the Security Policy on the Security Gateway:
> >
> >       * On Check Point Firewalls R82.20 and higher:
> >
> >         1. Connect to Gaia Portal on the Security Gateway.
> >
> >         2. In the left panel, navigate to the **System Management** section \> the **Security Management** page.
> >
> >         3. In the **Security Policy** section, select **Download and Install the policy from the Management Server**.
> >         4. Click the **Fetch policy** button.
> >
> >         Note - The **Security Policy** section is disabled, while there is no SIC connection.
> >       * On Check Point Firewalls R82.10 and lower:
> >
> >         1. Connect to the command line on the Security Gateway.
> >
> >         2. Log in to Gaia Clish or the Expert mode.
> >
> >         3. Run:
> >
> >            |----------------------------------------------------------------------------------------------------------------------------------------------------------------|
> >            | `cp_conf sic cert_pull <IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server> <Name of the Security Gateway Object>` |
> >
> >            Example:  
> >            `cp_conf sic cert_pull 192.168.3.57 MySecurityGateway1`
> >         4. Fetch the Security Policy on the Security Gateway:
> >
> >            * To fetch the Access Control policy, run:
> >
> >              `fw fetch -f`
> >
> >              By design, it is necessary to install the Access Control policy on a Security Gateway at least one time on the Management Server, before the Security Gateway can fetch it.
> >            * To fetch the Threat Prevention policy, run:
> >
> >              `fw amw fetch -f`
> >       * On Spark Firewalls:
> >
> >         1. Connect to the command line on the Spark Firewall.
> >
> >         2. Log in to Gaia Clish or the Expert mode.
> >
> >         3. Run:
> >
> >            |----------------------------------------------------------------------------------------------------------------------------------------------------------------|
> >            | `cp_conf sic cert_pull <IP Address of the Security Management Server / Domain Management Server / Smart-1 Cloud Server> <Name of the Security Gateway Object>` |
> >
> >            Example:  
> >            `cp_conf sic cert_pull 192.168.3.57 MySecurityGateway1`
> >         4. Fetch the Security Policy on the Spark Firewall:
> >
> >            * To fetch the Access Control policy, run:
> >
> >              `fw fetch -f`
> >
> >              By design, it is necessary to install the Access Control policy on a Security Gateway at least one time on the Management Server, before the Security Gateway can fetch it.
> >            * To fetch the Threat Prevention policy, run:
> >
> >              `fw amw fetch -f`

(4) Limitations {#TOC04}
------------------------

* Maestro Security Groups do not support completing the SIC establishment at a later time.

* ElasticXL Security Groups do not support completing the SIC establishment at a later time.

* After you complete the SIC establishment at a later time on a supported Security Gateway, the Management Server does not automatically update the interfaces and the device attributes in the Security Gateway object.

* In this procedure, the Management Server always installs the Desktop Policy (for Check Point Remote Access VPN clients with the Firewall feature). You cannot skip the Desktop Policy.

* On a Security Management Server / Multi-Domain Security Management Server running R82.20 and higher, the Security Gateway must complete the SIC establishment within the configured CRL fetch window (default: 30 days). Otherwise, the SIC establishment fails and must be re-initiated.

* This procedure does not suppor the installation of a QoS Policy.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
