Gateway HealthCheck Sample Report

CHECK POINT GATEWAY HEALTH CHECK REPORT

Prepared for

By

Date


Executive Summary

Check Point Professional Services have been engaged to run a Health Check to ensure the following devices are installed to Check Point best practices and optimized.

Hardware Name Cluster Version Jumbo
VMware Virtual Platform fw1-management R80.10 Take 91
VMware Virtual Platform FW1 Cluster1 R80.10 Take 112
VMware Virtual Platform FW2 Cluster1 R80.10 Take 112
Check Point 23800 vsx-1 VSXCluster2 R80.10 Take 103
Check Point 23800 vsx-2 VSXCluster2 R80.10 Take 103

The Health Check includes Summary Reports, Health Check Reports and any supporting documentation. This Consultant Report will summarize the findings and highlight any concerns or recommendations.


Management Review

The following findings have been identified on the R80.10 Security Management Server (fw1-management):

Topic Status Recommendations
Hotfix X Old version of JHF installed with known issues.
Licenses & Contracts ▲ Number of expired licenses and contracts.
Object Database X High amount of unused and duplicate objects.
Unassigned Policies ▲ 50% of policies are unassigned + increasing object count.
Session Timeout ▲ Default values increased.
Out of State X TCP out of state allowed. Security concern.
Disk Usage ▲ 85% disk usage.
Memory Usage i Swapping.
CPU Usage i Above expected value.
IO Wait i Low but consistent and should be monitored.
Local Users ▲ Improvement to prevent unauthorized access.
SNMP X Disabled.
IPS – Server Config ▲ Servers not defined.
Blade Updates ▲ Incorrect warnings.
Online Web Service ▲ Set to Background.
Implied Rules ▲ Logging implied rules.
Hit Count Database ▲ Many unused rules.

Each recommendation is rated as follows:

  • X Serious - Needs immediate attention
  • △ Attention - Needs attention
  • ✔ Good - No need for any action
  • i Informational

Professional Services

Hotfix

R80.10 Jumbo Hotfix Accumulator is an accumulation of stability and quality fixes resolving multiple issues in different products.

A backup taken from the installed take 91 will not restore correctly. Sk123352.

Recommended to install the latest jumbo to enhance feature set and improve stability.

Licenses and Contracts

The license repository contains a number of expired licenses and contracts.

License Expired
3 out of 27 licenses expired
14 out of 51 contracts expired

Object Database

The environment has a high number of duplicate and unused objects. The high number of duplicate objects is a concern; on policy push all used objects are verified. Remediating the duplicate objects would greatly improve policy push times.

Status Count Percent Remediation
Total Network Objects ✅ 4638 100%
Unused Network Objects ✘ 966 20.83%
Duplicate Network Objects ✘ 3162 68.18%
Nested Network Objects ✅ 41 0.88%
Total Services Objects ✅ 1283 100%
Unused Services Objects ✘ 208 16.21%
Nested Services Objects ✅ 26 2.03%

Unassigned Policies

Removing the unassigned policies eliminates the possibility for human error but more importantly, increases the amount of unused objects and allowed a greater potential for object database cleanup.

Policies Assigned
5 out of 10 not assigned

Session Timeouts

The default timeouts have been changed. Extending the session timeouts increase the gateway connection table utilizing additional memory.

Values Default Session Timeouts
TCP start timeout: 60 seconds TCP start timeout: 25 seconds
TCP session timeout: 1800 seconds TCP session timeout: 3600 seconds
TCP end timeout: 50 seconds TCP end timeout: 20 seconds
UDP virtual session timeout: 90 seconds UDP virtual session timeout: 40 seconds
ICMP virtual session timeout: 30 seconds ICMP virtual session timeout: 30 seconds
Other IP protocols virtual session timeout: 60 seconds Other IP protocols virtual session timeout: 60 seconds
SCTP start timeout: 30 seconds SCTP start timeout: 30 seconds
SCTP session timeout: 3600 seconds SCTP session timeout: 3600 seconds
SCTP end timeout: 20 seconds SCTP end timeout: 20 seconds

Out of State

TCP out of state packets are allowed for all gateways. Allowing out of state packets allows the potential of a Denial of Service attack to all protected servers.

Highly recommended to prevent out of state packets; especially as the reviewed gateways are on the internet perimeter.

Disk Usage

Log directory at 85% usage:

Filesystem Type Size Used Avail Use% Mounted on
/dev/mapper/vg_splat-lv_current ext3 47G 16G 29G 37% /
/dev/sda1 ext3 289M 24M 251M 9% /boot
/dev/mapper/vg_splat-lv_log ext3 97G 78G 15G 85% /var/log
tmpfs tmpfs 16G 4.0K 16G 1% /dev/shm

Large files that could be removed to increase available space:

[Expert@fwl-management:0]# find / -size +500M
/home/admin/fwl-management_3_9_2018_13_07_migrate_export_out.tgz
/home/admin/fwl-management_8_5_2018_15_06_migrate_export_out.tgz
/var/log/CPackup/bachups/6_0c_18_16_migate-export.tgz
/var/log/CPRA/repository/CheckPointCPRUpdatee#All#6.0####BUNDLE_R80_10_JUMBO_HF#91/Check_Point_R80_10_JUMBO_HF_Bundle_791_sk116380_FULL.tgz
/var/log/dump/usermode/fvm.4293.core.gz

Memory Usage

The system currently has sufficient memory; but prior to the 3rd September memory usage was at around 100%.

current usage: Total Used Free Shared Buffers Cached
Mem: 32823288 31546036 1277252 0 1078096 11319580
+/ buffers/cache: 19148360 13674928
Swap: 39551744 120 39551624
Total: 66375032 31546156 34828876

CPU Usage

CPU usage is within acceptable values, but as it’s a VM an additional CPU or two would improve the user experience.


Local Users

Both CLI and SmartConsole have users defined with local accounts only. It is recommended to configure AAA; so when users leave the company and are removed from Active Directory, they are automatically restricted access.

Name Expiration Date Profile Authentication Method
admin Dec 31,2030 Super User OS Password
Dec 31,2018 Super User Check Point Password
Dec 31,2018 read_write Check Point Password
Dec 31,2030 read_write Check Point Password
Dec 31,2020 read_write Check Point Password
Jan 31,2020 read_write Check Point Password

SNMP

SNMP is used to monitor the system and identify any potential issues. SNMP agent is disabled.

IPS - Server Configuration

Some IPS protections are only applied against defined servers. Web, Mail, and DNS servers need to be defined in the host objects for these IPS protections to take effect.

Blade Updates

The management is incorrectly stating that blades are not up to date on the gateways. Install the latest Jumbo on all devices and install the latest SmartConsole to remediate the cosmetic issue.


Online Web Services – Threat Prevention

Threat Prevention blade connections are allowed until they are categorized:

  • Block connections when the web service is unavailable
  • Resource classification mode
  • Background - requests are allowed until categorization is complete
  • Hold - requests are blocked until categorization is complete

Implied Rules

Logging implied rules is recommended only to troubleshoot connectivity or VPN issues as it adds overhead to the gateway and management.


Hit Count Database

There are many rules that have not been hit in the last 3 months. Only required access to be allowed through the gateway; if the rule is not in use then it is not required.

Cluster1 Cluster Review

The following findings have been identified on the R80.10 VSec cluster:

Topic Status Recommendations
Hotfix X Gateway vulnerability to be remediated with latest JHF.
NAT Cache i
Misplaced Rules A Performance can be improved by moving rules within the policy.
VOIP A Firewall Early NAT chain enabled but no VOIP traffic passing gateway.
Snapshot/Backup A No backups scheduled.
AAA A Local accounts only defined.
Interface buffers X Inconsistent values set.
Fragments A Determine source of fragments.
Sync X Sync issues detected.
Zombie Processes X 5 zombie processes detected.
Weak Ciphers A Default ciphers configured.
SNMP Version X Insecure version of SNMP configured.
HA State A Recent change of state.
Logging A Non-resilient logging.
Anti-Spoofing X Not configured correctly.
Drop Templates A Optimization possible.
NTP X Version configured open to exploit.
ARP X sk18463
Stealth X Missing.


Hotfix

R80.10 Jumbo Hotfix Accumulator is an accumulation of stability and quality fixes resolving multiple issues in different products.


NAT Cache

NAT Cache limit has exceeded. This will not cause any problems, as these connections will be matched against the NAT rules instead of the NAT cache table.


Misplaced Rules

Review the policy and move rules with the highest hit count as far to the top of the policy as possible.


Snapshot/Backup

There are no Snapshots, Backups or Scheduled Backups on the system.


AAA

AAA is used to authorize, authenticate and account user access. Only local user accounts are configured on the gateway:


Weak Ciphers

Weak Ciphers are allowed to and through the gateway. If in a PCI environment then they need to be hard disabled, if not then they can be prevented in security and IPS policy.


Sync

High delay in sync traffic reported with minimal out of RX-Drp and RX-Ovr on the Sync interface.

ARP

Detects recent errors. Review physical connections as needed.


NTP

NTP versions 1-3 are no longer maintained, delays in security may occur.


Consultant Overview

The main concern in the environment is security; gateways susceptible to vulnerabilities, no stealth rules, insecure versions of SNMP and NTP in use. Access to VS 0 not logged and open to “Any” source, non-resilient logging/auditing, no AAA measure available.

On the plus side, the systems are not under any particular load. Check Point PS would recommend utilizing this resource to enable HTTPS Inspection to enhance perimeter security.

Overall, systems perform well and have resources available for further enhancements but should address identified issues immediately for stability and security.


Disclaimer

The Customer hereby attests and acknowledges that the Check Point Professional Services Engineer has completed the project work described. This work meets the requirements specified by the Customer and has been completed to the satisfaction of the Customer.