CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-08
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 55
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Firewall Log monitoring

Hi,

I am monitoring FW logs from last few weeks based on following :-
1. Packet drops: Reason for their drop, Rule (clean up, stealht rule or any other rule) & chekc with the concerned for their reason to reduce noise.
2. Port scanning attempt on FW
3. Address spoofing messages if any.
4. Smartdefense entries (thoughw e have not configured it fully)
5. Firewall Changes done in a months time and they are complaint or not.i.e Firewall change request was raised or not.
6. Admin/other user login success/failure

but How can we ehance FW log monitoring, we've configured fwlogsum.
but how to detect port scanning in logging (I've enabled in smartdefense), and other malicious traffic details, like virus etc.

Any suggesions are welcomed.
thx
Yogi
Reply With Quote
  #2 (permalink)  
Old 2007-01-08
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Firewall Log monitoring

Eventia suite? Check point's own analyzer and reporter will do everything you are asking for and more.
Reply With Quote
  #3 (permalink)  
Old 2007-01-09
chandruenn chandruenn is offline
Junior Member
 
Join Date: 2006-12-06
Posts: 4
Rep Power: 0
chandruenn has an average reputation (10+)
Default Re: Firewall Log monitoring

Hi,

I am very new to cpfw.

But, i am installing the cpfw on SPLAT with HA. Meanwhile, the rules setup has been done. I am facing some problems on sending & receiving the mails.

The topology is like, router, firewall R62.

At the same time i am in the stage to install the checkpoint vpn.

So, can anyone pls help me out on the same.

thanks in advance.

chandru.
Reply With Quote
  #4 (permalink)  
Old 2007-01-12
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 55
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Re: Firewall Log monitoring

Hi,
whats ut topology,
What rules have u configured.
have u configured NAtting?
do u ve ACL's on perimter router.

VPN bet two CP or CP & Cisco VPN etc.

revert.
YT
Reply With Quote
  #5 (permalink)  
Old 2007-01-12
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 55
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Re: Firewall Log monitoring

Hi,
thx but eventia is a priced product.
any free tool?

Thx
YT
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:28.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0