Configuring Check Point NGX VPN-1/FireWall-1

In this chapter we will examine the functionality of SmartUpdate as a SmartConsole client in your Check Point environment. This client is designed to simplify the administrative tasks of software and license management. The firewall administrator has a single tool for viewing the list of software and licenses for all modules managed by a specific SmartCenter Server. The license and package repositories are data stores where software packages and licenses can be distributed to the managed modules.
Centralized and local licenses can be attached or removed from modules as necessary regardless of the complexity of your environment. Upgrades and patches for Check Point and OPSEC certified applications can be remotely distributed to various modules. Additionally IPSO and SecurePlatform operating systems can be upgraded using SmartUpdate.
In NGX there are new features available in SmartUpdate. Upgrades can be performed to a version earlier than the current SmartCenter version. Upgrading SmartPlatform includes options for reverting to specific images. Packages can be distributed to remote devices prior to performing the actual upgrade. The last notable feature addition is the ability to generate a CPInfo file for a specific module. There are minor column changes in the License Management and License Repository tables.
Using this tool to upgrade the software or operating system does require specific licensing for your SmartCenter Server and is based upon the number of managed devices. The value of having a centralized location to manage patching and upgrading increases with the size and complexity of your environment.