CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Eventia Analyzer/Reporter/SmartView Reporter
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-17
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 54
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default What should be monitored in FW log?

Hey guys (gals too, see folks i never forget gals, i dont know whether our CPUG has gals too:)

What should be monitored in FW logs?
In my view:-
1. denied packets? reasons for them and try to reduce noise
2. port scanning
3. malicous activity (but how to check it in logs)
4. ?
u need to tell me.
thx
Yogi
Reply With Quote
  #2 (permalink)  
Old 2006-11-17
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Whats should be monitored in FW log

1. Anti-spoofing drops - particularly on the internal interface.

2. Failed logins, including remote access

3. Outbound traffic attempts that should not be there (assumes you have a restrictive outbound policy) - I actually find this one very valuable if the network default route points to the firewall.

4. SmartDefense drops trying to come in on the external interface.

Ray
Reply With Quote
  #3 (permalink)  
Old 2006-11-17
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 534
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Whats should be monitored in FW log

Quote:
Originally Posted by yogi_ccse View Post
Hey guys (gals too, see folks i never forget gals, i dont know whether our CPUG has gals too:)
Oh, there are a couple here, but I'm sure they're quietly laughing at us.

"Geeks", says one.

"Dorks", says the other.
Reply With Quote
  #4 (permalink)  
Old 2006-11-18
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 54
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Re: Whats should be monitored in FW log

Thanks Dude.
i am expecting some more from point of malicious activities to be monitored.?
is there any tool (Free) which can given such reports:-
1. denied packets.
2. por scanning
3. malicious atempts etc.

we r using fwlogsum but it says for dropped pkts, we also have snare but its in inside nw so cannot send cp logs to it.
thx
Yogi
Reply With Quote
  #5 (permalink)  
Old 2006-11-18
Robby Cauwerts Robby Cauwerts is offline
Senior Member
 
Join Date: 2006-10-05
Location: Belgium
Posts: 108
Rep Power: 2
Robby Cauwerts has an average reputation (10+)
Default Re: Whats should be monitored in FW log

Quote:
Originally Posted by yogi_ccse View Post
is there any tool (Free) which can given such reports:-
1. denied packets.
2. por scanning
3. malicious atempts etc.
Yogi
Check Point has its Eventia Analyzer that does event correlation.
But there are a lot of other products that do +/- the same thing.
If you just want the reporting/graphs then take a look at Eventia Reporter
Reply With Quote
  #6 (permalink)  
Old 2006-11-18
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 54
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Re: Whats should be monitored in FW log

Hi,

Is Eventia reporter free? If not whats is its price? what needs to be done to use it?
Thanks.
Yogi
Reply With Quote
  #7 (permalink)  
Old 2006-11-18
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Whats should be monitored in FW log

Quote:
Originally Posted by yogi_ccse View Post
Is Eventia reporter free? If not whats is its price? what needs to be done to use it?
CPMP-EVA-5 US$18,000 List

Supports one SmartCenter/CMA and up to five devices

If you are running NGX (R60 or latter) it installs on a server and an object gets created in the SC for it.

It is a really easy product to get up and running. Its even pretty easy to get it doing useful stuff.
Reply With Quote
  #8 (permalink)  
Old 2006-11-19
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: What should be monitored in FW log?

Sorry, I guess I should have explained these a bit better. My philosophy is that if someone paints a target on your back, they are getting in regardless of what you do. You need to throw enough hurdles in front of them that their activities get noticed and you need to consider what happens if they do not get stopped and they need to get out. Outbound monitoring is very useful in this regard.

"1. Anti-spoofing drops - particularly on the internal interface."

Improper IP's on the wrong interface is either a sign of misconfiguration or trouble. One example I see is someone who left their wireless card on and got associated with an outside wireless access point. We start seeing their WAP-assigned IP on the internal network. A helpful one is that a momentary outage on our WAN, not long enough to trip network monitors, will always show up as an anti-spoof due to the default route opointing to the firewall.

"2. Failed logins, including remote access"

Kind of self-explanatory. We use ICA certificates and I usually find expired certificates before the people call the Help Desk. In one case, a terminated employee's laptop was not collected by HR even though they told us it was.

"3. Outbound traffic attempts that should not be there (assumes you have a restrictive outbound policy) - I actually find this one very valuable if the network default route points to the firewall."

SMTP outbound from a device that's not a mail server. POP3 from people trying to connect to home email accounts. FTP uploads from people that are not permitted to upload. If you do get a compromised computer and it tries to establish outbound connections, this monitoring will show it fast.

It also shows non-company computers on your network trying to establish outbound connections. Skype really lights up the log files if you have a restrictive outbound policy.

"4. SmartDefense drops trying to come in on the external interface."

This one usually doesn't show too much, but the other day it showed an IP in China trying to hit us with a resource starvation attack (MSS = 0) for seven solid hours.

Ray
Reply With Quote
  #9 (permalink)  
Old 2006-11-19
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Whats should be monitored in FW log

Quote:
Originally Posted by chillyjim View Post
CPMP-EVA-5 US$18,000 List

Supports one SmartCenter/CMA and up to five devices
Jim, I think you accidentally quoted Analyzer, not Reporter. Reporter is a lot cheaper if you have only one gateway you want to monitor, $2,000 list if you have a 500 or less IP license, $5,000 list for unlimited IPs.

http://pricelist.checkpoint.com or http://pricelist.checkpoint.com/US/P...oduct=CPMP-EVR

Ray
Reply With Quote
  #10 (permalink)  
Old 2006-11-20
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 54
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Re: What should be monitored in FW log?

Thanks RayPesek for clarifying both.

I feel checkpoint should give Eventia Reporter as free tool.
as people who want more will neway go for some SIM solution like eventia analyzer/ Cisco CSMARS, NetiQ, Netforensics etc.
Thanks.
Yogi.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:56.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0