CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 3 of 3

Thread: IPS with port mirror

  1. #1
    Join Date
    2016-08-11
    Posts
    11
    Rep Power
    0

    Default IPS with port mirror

    Hi All,

    Before configuring this i have checked ;

    sk88980 - How to configure a Security Policy for Mirror Port Use
    sk 101670 - Monitor Mode on Gaia OS and SecurePlatform OS
    Thread: How to setup a new IPS sensor with 77.30? on CPUG

    Topology is like this;

    Click image for larger version. 

Name:	IDS Oca para CPUG v1.1.jpg 
Views:	375 
Size:	223.7 KB 
ID:	1155


    I configured all interfaces with no IP and monitor mode enabled. (Except the one for management, of course)
    Disabled drop out of state
    Profile is in troubleshooting mode
    And I think that's it.

    But it's not really caughting anything. Is the configuration OK? Some other input I should give you guys to understand the scenario?

    PD: I have checked and there are some RX drops, but it should be caughting something anyway.

    fw ctl zdebug drop shows;

    ;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=6 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 1;

    ;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=6 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 1;

    ;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=6 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 1;

    ;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=6 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 1;

    ;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=6 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 1;

    ;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=6 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 1;





    Thanks in advance
    Attached Thumbnails Attached Thumbnails Click image for larger version. 

Name:	IDS Oca para CPUG v1.0.jpg 
Views:	231 
Size:	245.9 KB 
ID:	1154  
    Last edited by jlobera; 2016-08-26 at 16:12.

  2. #2
    Join Date
    2014-06-18
    Location
    Kiel
    Posts
    12
    Rep Power
    0

    Default Re: IPS with port mirror

    Quote Originally Posted by jlobera View Post
    ;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=6 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 1;
    What does the firewall rulebase look like? "Any source, any destination, any service: Allow"?

  3. #3
    Join Date
    2016-08-11
    Posts
    11
    Rep Power
    0

    Default Re: IPS with port mirror

    Quote Originally Posted by ofink View Post
    What does the firewall rulebase look like? "Any source, any destination, any service: Allow"?
    Yes. Thats it for the rule base

Similar Threads

  1. How to indentify an attack on mirror port
    By rgbfilho in forum IPS Blade (Formerly SmartDefense)
    Replies: 5
    Last Post: 2015-03-11, 11:10
  2. VoIP problem with mirror port
    By rgbfilho in forum Voice over IP Blade (VoIP)
    Replies: 1
    Last Post: 2015-02-13, 08:51
  3. Failed to create mirror cma ....
    By pebbles5 in forum Provider-1 (Multi-Domain Management)
    Replies: 1
    Last Post: 2010-11-05, 13:33
  4. Looking for Cli commands for checking raid and mirror conditions
    By eduardw in forum Check Point SecurePlatform (SPLAT)
    Replies: 4
    Last Post: 2008-12-01, 17:50
  5. Dell Server 2950-III and mirror RAID-1 and SPLAT NGx R65
    By cciesec2006 in forum Check Point SecurePlatform (SPLAT)
    Replies: 4
    Last Post: 2008-05-13, 19:10

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •