Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Current »

About the Device

Checkpoint Security devices are leading provider in Firewall/NIPS/NIDS Systems, it is a network security appliance that detects unauthorized activity over the network, analyzing traffic in real time and letting users quickly respond to security breaches. Check Point's leading cyber-security platform now includes threat emulation and HyperSpect performance enhancing technology along with Anti-bot.

Device Information

 Entity

Particulars

Vendor Name

Check Point

Product Name

Next Generation Firewalls (NGFW)

Type of Device

Hosted

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol

Log Collection Method

Check Point

 CHECKPOINT_FIREWALL

Syslog

CyberHub

Port Requirements

Source

Destination

Port

Check Point

CyberHub

601 (TCP)

Device Configuration

Prerequisites

Log Exporter: Check Point Log Export Utility, Utility details and Installation instructions and packages are available at https://support.checkpoint.com/results/sk/sk122323

In order to configure a new target for the logs do the following on the log server:

  1. Login to log server as Admin

  2. Get in to expert mode to edit the configuration

  3. Execute the below command to forward logs to syslog server

cp_log_export add name <New Name> domain-server <Domain-Server-IP> target-server <CyberHub IP> target-port <target-port> protocol tcp format syslog read-mode semi-unified
  1. Also, execute the below command to restart the exporter service.

cp_log_export restartname <name> [domain-server <domain-server>]

For the above 2 commands, The Argument <domain-server> is applicable only on multi-domain management machines

image-20240105-114842.png

Integration Parameters

Parameters required from customer for Integration.

Property

Default Value

Description

IP Address

Check Point interface IP address

Hostname or IP address of the device which forwards logs to the CyberHub

  • No labels