CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-23
walcat_0 walcat_0 is offline
Member
 
Join Date: 2006-05-23
Location: New Zealand
Posts: 56
Rep Power: 3
walcat_0 has an average reputation (10+)
Default System Integrity

Hi,

What would be the best way to do an audit of the firewalls to see who or if anyone had gained access to them that wasn't supposed too ? Is there an easy way of doing this on Solaris & Nokia ?

Any help would be appreciated.

Thanks
Reply With Quote
  #2 (permalink)  
Old 2007-01-23
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 891
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: System Integrity

It's not an easy question to answer.

How well are the SmartCenter and enforcement modules physically protected?

How well is the enforcement module protecting itself? Is there a rule that only allows access to it from certain IP addresses or can anyone "touch" it?

Does cpconfig on the SmartCenter restrict SmartConsole access to just certain IP addresses or did someone allow an entire subnet or * ?

How well are the SmartCenter and enforcement modules patched? Are OS patches applied in a timely basis? (Can someone use a remote exploit to gain admin access without knowing a set of credentials? Are there unnecessary services running that could be used in a remote exploit?)

How do administrators authenticate? User name and password only? Certificates? Is it the same one for everyone? Is anyone using the "admin" account instead of their own account? Are lockouts configured? How are alerts distributed?

How often do authorized administrators login and what do they check? You can use filters on the Audit tab to see this information. (i.e. Is anyone paying attention?)

How often are the logs deleted?

What exactly are you looking for? A routine audit or suspected abuse?

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:57.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0