About the Device
Checkpoint Security devices are leading provider in Firewall/NIPS/NIDS Systems, it is a network security appliance that detects unauthorized activity over the network, analyzing traffic in real time and letting users quickly respond to security breaches. Check Point's leading cyber-security platform now includes threat emulation and HyperSpect performance enhancing technology along with Anti-bot.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Check Point |
Product Name | Next Generation Firewalls (NGFW) |
Type of Device | Hosted |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol | Log Collection Method |
---|---|---|---|
Check Point | CHECKPOINT_FIREWALL | Syslog | CyberHub |
Port Requirements
Source | Destination | Port |
---|---|---|
Check Point | CyberHub | 601 (TCP) |
Device Configuration
Prerequisites
Log Exporter: Check Point Log Export Utility, Utility details and Installation instructions and packages are available at https://support.checkpoint.com/results/sk/sk122323
In order to configure a new target for the logs do the following on the log server:
Login to log server as Admin
Get in to expert mode to edit the configuration
Execute the below command to forward logs to syslog server
cp_log_export add name <New Name> domain-server <Domain-Server-IP> target-server <CyberHub IP> target-port <target-port> protocol tcp format syslog read-mode semi-unified
Also, execute the below command to restart the exporter service.
cp_log_export restartname <name> [domain-server <domain-server>]
For the above 2 commands, The Argument <domain-server> is applicable only on multi-domain management machines
Integration Parameters
Parameters required from customer for Integration.
Property | Default Value | Description |
---|---|---|
IP Address | Check Point interface IP address | Hostname or IP address of the device which forwards logs to the CyberHub |