CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-25
shaz86 shaz86 is offline
Junior Member
 
Join Date: 2006-05-24
Posts: 3
Rep Power: 0
shaz86 has an average reputation (10+)
Default Rule Consolidation

Hey I'm a new checkpoint user and I could use some tips/help on this project I'm working on. I need to clean up and consolidate the rules for a really complicated and bloated rule set (500+ rules). Most of the rules DONT have logging enabled and I want to know if there is an easy way to check if the rules are being used or not. Also any other tips on how to consolidate the rules would be very useful. Thanks!
Reply With Quote
  #2 (permalink)  
Old 2006-05-25
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Rule Consolidation

IMHO, Reporter is helpful, but you will need rules with log. I don't see another way.
Reply With Quote
  #3 (permalink)  
Old 2006-05-25
shaz86 shaz86 is offline
Junior Member
 
Join Date: 2006-05-24
Posts: 3
Rep Power: 0
shaz86 has an average reputation (10+)
Default Re: Rule Consolidation

I was hoping that wouldn't be the case, logging so many rules is almost impossible. Unfortunately I don't have reporter either. If anyone has any other tips, it would really help!
Reply With Quote
  #4 (permalink)  
Old 2006-05-26
donshoutarp donshoutarp is offline
Member
 
Join Date: 2005-09-23
Posts: 75
Rep Power: 3
donshoutarp has an average reputation (10+)
Default Re: Rule Consolidation

You could turn logging on for a couple of rules and monitor their usage for a month or so (or whatever you think necesssary), turn off logging and turn it on for other rules.

This would take a while, but it may work.
Reply With Quote
  #5 (permalink)  
Old 2006-05-28
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: Rule Consolidation

You can use SmartViev Monitor to get some information.

Create new report "File > New > Traffic View"
Create either history "Top Matched Security Rules On all interfaces" either RealTime "Security Rules" report. In the real-time modify Max Rules To Show (unfortunately max is 50, but not 500+ like in yours situation)

Eventia Reporter also includes very useful report: Standard > Security > Rule Base Analyzer. Here is exempt from description:

---
This report presents an analysis of FireWall-1 rule base.

The report can be used to determine which rules are used the most, which rules are used infrequently and which rules are never used. It can also be used to determine which rules are matched by service, source, and destination.

Rules are presented by their location in the policy at the time of report generation, while their usage data is gathered by their unique ID where possible. If no unique ID data is available, the rules are marked with an asterisk.
---

I guess logging do not need to be enabled on all rules to use this report. Am I wrong?
Reply With Quote
  #6 (permalink)  
Old 2006-05-29
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Rule Consolidation

Quote:
I guess logging do not need to be enabled on all rules to use this report. Am I wrong?
You right. I mistook about log options. I forgot that consolidation rules are individual.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:19.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0