CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    Courses Starting (2010) 4/12, 5/10, 6/7, 7/12.
2. Save the Date!  CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn, Facebook, and Ning.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Interoperability
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2010-01-29
Junior Member
 
Join Date: 2009-11-04
Posts: 14
Rep Power: 0
skipper has an average reputation (10+)
Default RSA Envision and NGXR65

Hi,

I have a SPLAT StandAlone NGXR65 HFA50 and a Envision Server.
There is no documentation in checkpoint support and i'd like
to use Envision to receive logs.
I have been trying with no success.
Another thing that had caught my attention was that if the node is added as a checkpoint object, it appears in Smart View Monitor, but disconnected.
Should the Envision, as an Opsec Device, be shown in Smart View monitor?
I have a manual from RSA but it doesnt says anything about it.
What do i need to make the management send the logs to my envision server?? and to be shown online in Smart View Monitor?

I hope i was clear enough.

Thanks in advance,

Regards, Lucas.
Reply With Quote
  #2 (permalink)  
Old 2010-01-29
Member
 
Join Date: 2009-04-14
Location: NE Ohio
Posts: 39
Rep Power: 0
bmolnar has an average reputation (10+)
Default Re: RSA Envision and NGXR65

For an OPSEC connection, you have to add a new application under the "Servers and OPSEC Applications" tab which is the 4th tab in the left-pane. (Looks like a server and a gear) You should also add the server name & IP as a regular host object because you'll need it for the OPSEC set up screen. From there, you can mark LEA and establish SIC communication. The enVision is listed under Network_Intelligence. On your Envision Server you should hopefully have options to accept an LEA connection from your SPLAT server.

Last edited by bmolnar; 2010-01-29 at 06:45.
Reply With Quote
  #3 (permalink)  
Old 2010-01-29
Junior Member
 
Join Date: 2009-11-04
Posts: 14
Rep Power: 0
skipper has an average reputation (10+)
Default Re: RSA Envision and NGXR65

Ok,

I need to establish SIC, there is no such option on Envision or at least i can't find it. Any advice??

Thanks in advance.
Reply With Quote
  #4 (permalink)  
Old 2010-01-29
Member
 
Join Date: 2009-04-14
Location: NE Ohio
Posts: 39
Rep Power: 0
bmolnar has an average reputation (10+)
Default Re: RSA Envision and NGXR65

I've never used the RSA Envision product before, but hopefully they provide additional documentation on their website. It might be as easy as editing a few files on the Envision server.

Here are steps on how to set it up with Splunk which may or may not help.
Community:Configure OPSEC LEA input - Splunk Wiki
Personally, I didn't have to edit the fwopsec.conf file to get my LogLogic device working via LEA and CPMI.
Reply With Quote
  #5 (permalink)  
Old 2010-01-29
Junior Member
 
Join Date: 2009-08-06
Posts: 9
Rep Power: 0
EJSTL has an average reputation (10+)
Default Re: RSA Envision and NGXR65

You won't see the envision server in monitor; you will just create a generic host object representing its ip for use in a rule and to associate to the opsec object (which is not a network object and is not listed in the objects tree).

Just follow the RSA pdf word for word and you shouldn't have any issues pulling logs from your management server via LEA.
Reply With Quote
  #6 (permalink)  
Old 2010-01-29
Junior Member
 
Join Date: 2009-08-06
Posts: 9
Rep Power: 0
EJSTL has an average reputation (10+)
Default Re: RSA Envision and NGXR65

Quick note; SIC is going to be established under the "Manage LEA Client Service" screen from the envision UI. Should all be in the RSA configuration guide.
Reply With Quote
Reply

Tags
envision rsa ngxr65

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:34.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2