checkpoint

This tag is associated with 1 posts


Application Control Next Generation Firewalls

Checkpoint introduced Application control policies in their R75 version recently, while traditional firewalls like ASA and SRX perform control based on protocols, ports and IP, the new next generation firewalls in addition provides granular control by application and users using these applications.

The only other vendor doing this in the security space is a new company called Paloalto networks which appears to have initiated this concept for good.

The checkpoint App wiki is a great resource to see what application controls are possible.

http://appwiki.checkpoint.com/appwikisdb/public.htm

Enabling and configuring SNMP in Checkpoint Nokia

Warning, performing the below actions will do a cpstop & cpstart.

Using CLI

> Login to the Checkpoint Nokia appliance

> Type ‘cpconfig’

> Select ‘SNMP Extension’

> Select ‘y’ to activate the SNMP daemon

> Exit

Using Voyager

> Login > Configuration > SNMP

Command to gracefully failover Checkpoint Splat firewalls.

Use the command below to gracefully failover Checkpoint Splat firewalls in cluster.

clusterXL_admin <up|down>

Installing Eventia Reporter in Checkpoint Splat

To install Eventia Reporter on an already installed checkpoint system,

> run the command sysconfig.

> Select option ‘Product Installation’

This option is not available using the browser. Note that you will need to have a license to use this feature and its licensed per gateway.