Gateway HealthCheck Sample Report
CHECK POINT GATEWAY HEALTH CHECK REPORT
Prepared for
By
Date
Executive Summary
Check Point Professional Services have been engaged to run a Health Check to ensure the following devices are installed to Check Point best practices and optimized.
| Hardware Name | Cluster | Version | Jumbo |
|---|---|---|---|
| VMware Virtual Platform | fw1-management | R80.10 | Take 91 |
| VMware Virtual Platform | FW1 Cluster1 | R80.10 | Take 112 |
| VMware Virtual Platform | FW2 Cluster1 | R80.10 | Take 112 |
| Check Point 23800 | vsx-1 VSXCluster2 | R80.10 | Take 103 |
| Check Point 23800 | vsx-2 VSXCluster2 | R80.10 | Take 103 |
The Health Check includes Summary Reports, Health Check Reports and any supporting documentation. This Consultant Report will summarize the findings and highlight any concerns or recommendations.
Management Review
The following findings have been identified on the R80.10 Security Management Server (fw1-management):
| Topic | Status | Recommendations |
|---|---|---|
| Hotfix | X | Old version of JHF installed with known issues. |
| Licenses & Contracts | ▲ | Number of expired licenses and contracts. |
| Object Database | X | High amount of unused and duplicate objects. |
| Unassigned Policies | ▲ | 50% of policies are unassigned + increasing object count. |
| Session Timeout | ▲ | Default values increased. |
| Out of State | X | TCP out of state allowed. Security concern. |
| Disk Usage | ▲ | 85% disk usage. |
| Memory Usage | i | Swapping. |
| CPU Usage | i | Above expected value. |
| IO Wait | i | Low but consistent and should be monitored. |
| Local Users | ▲ | Improvement to prevent unauthorized access. |
| SNMP | X | Disabled. |
| IPS – Server Config | ▲ | Servers not defined. |
| Blade Updates | ▲ | Incorrect warnings. |
| Online Web Service | ▲ | Set to Background. |
| Implied Rules | ▲ | Logging implied rules. |
| Hit Count Database | ▲ | Many unused rules. |
Each recommendation is rated as follows:
- X Serious - Needs immediate attention
- △ Attention - Needs attention
- ✔ Good - No need for any action
- i Informational
Professional Services
Hotfix
R80.10 Jumbo Hotfix Accumulator is an accumulation of stability and quality fixes resolving multiple issues in different products.
A backup taken from the installed take 91 will not restore correctly. Sk123352.
Recommended to install the latest jumbo to enhance feature set and improve stability.
Licenses and Contracts
The license repository contains a number of expired licenses and contracts.
| License | Expired |
|---|---|
| 3 out of 27 licenses | expired |
| 14 out of 51 contracts | expired |
Object Database
The environment has a high number of duplicate and unused objects. The high number of duplicate objects is a concern; on policy push all used objects are verified. Remediating the duplicate objects would greatly improve policy push times.
| Status | Count | Percent | Remediation |
|---|---|---|---|
| Total Network Objects | ✅ | 4638 | 100% |
| Unused Network Objects | ✘ | 966 | 20.83% |
| Duplicate Network Objects | ✘ | 3162 | 68.18% |
| Nested Network Objects | ✅ | 41 | 0.88% |
| Total Services Objects | ✅ | 1283 | 100% |
| Unused Services Objects | ✘ | 208 | 16.21% |
| Nested Services Objects | ✅ | 26 | 2.03% |
Unassigned Policies
Removing the unassigned policies eliminates the possibility for human error but more importantly, increases the amount of unused objects and allowed a greater potential for object database cleanup.
| Policies | Assigned |
|---|---|
| 5 out of 10 | not assigned |
Session Timeouts
The default timeouts have been changed. Extending the session timeouts increase the gateway connection table utilizing additional memory.
| Default Session Timeouts | |
|---|---|
| TCP start timeout: 60 seconds | TCP start timeout: 25 seconds |
| TCP session timeout: 1800 seconds | TCP session timeout: 3600 seconds |
| TCP end timeout: 50 seconds | TCP end timeout: 20 seconds |
| UDP virtual session timeout: 90 seconds | UDP virtual session timeout: 40 seconds |
| ICMP virtual session timeout: 30 seconds | ICMP virtual session timeout: 30 seconds |
| Other IP protocols virtual session timeout: 60 seconds | Other IP protocols virtual session timeout: 60 seconds |
| SCTP start timeout: 30 seconds | SCTP start timeout: 30 seconds |
| SCTP session timeout: 3600 seconds | SCTP session timeout: 3600 seconds |
| SCTP end timeout: 20 seconds | SCTP end timeout: 20 seconds |
Out of State
TCP out of state packets are allowed for all gateways. Allowing out of state packets allows the potential of a Denial of Service attack to all protected servers.
Highly recommended to prevent out of state packets; especially as the reviewed gateways are on the internet perimeter.
Disk Usage
Log directory at 85% usage:
| Filesystem | Type | Size | Used | Avail | Use% | Mounted on |
|---|---|---|---|---|---|---|
| /dev/mapper/vg_splat-lv_current | ext3 | 47G | 16G | 29G | 37% | / |
| /dev/sda1 | ext3 | 289M | 24M | 251M | 9% | /boot |
| /dev/mapper/vg_splat-lv_log | ext3 | 97G | 78G | 15G | 85% | /var/log |
| tmpfs | tmpfs | 16G | 4.0K | 16G | 1% | /dev/shm |
Large files that could be removed to increase available space:
[Expert@fwl-management:0]# find / -size +500M
/home/admin/fwl-management_3_9_2018_13_07_migrate_export_out.tgz
/home/admin/fwl-management_8_5_2018_15_06_migrate_export_out.tgz
/var/log/CPackup/bachups/6_0c_18_16_migate-export.tgz
/var/log/CPRA/repository/CheckPointCPRUpdatee#All#6.0####BUNDLE_R80_10_JUMBO_HF#91/Check_Point_R80_10_JUMBO_HF_Bundle_791_sk116380_FULL.tgz
/var/log/dump/usermode/fvm.4293.core.gz
Memory Usage
The system currently has sufficient memory; but prior to the 3rd September memory usage was at around 100%.
| current usage: | Total | Used | Free | Shared | Buffers | Cached |
|---|---|---|---|---|---|---|
| Mem: | 32823288 | 31546036 | 1277252 | 0 | 1078096 | 11319580 |
| +/ buffers/cache: | 19148360 | 13674928 | ||||
| Swap: | 39551744 | 120 | 39551624 | |||
| Total: | 66375032 | 31546156 | 34828876 |
CPU Usage
CPU usage is within acceptable values, but as it’s a VM an additional CPU or two would improve the user experience.
Local Users
Both CLI and SmartConsole have users defined with local accounts only. It is recommended to configure AAA; so when users leave the company and are removed from Active Directory, they are automatically restricted access.
| Name | Expiration Date | Profile | Authentication Method |
|---|---|---|---|
| admin | Dec 31,2030 | Super User | OS Password |
| Dec 31,2018 | Super User | Check Point Password | |
| Dec 31,2018 | read_write | Check Point Password | |
| Dec 31,2030 | read_write | Check Point Password | |
| Dec 31,2020 | read_write | Check Point Password | |
| Jan 31,2020 | read_write | Check Point Password |
SNMP
SNMP is used to monitor the system and identify any potential issues. SNMP agent is disabled.
IPS - Server Configuration
Some IPS protections are only applied against defined servers. Web, Mail, and DNS servers need to be defined in the host objects for these IPS protections to take effect.
Blade Updates
The management is incorrectly stating that blades are not up to date on the gateways. Install the latest Jumbo on all devices and install the latest SmartConsole to remediate the cosmetic issue.
Online Web Services – Threat Prevention
Threat Prevention blade connections are allowed until they are categorized:
- Block connections when the web service is unavailable
- Resource classification mode
- Background - requests are allowed until categorization is complete
- Hold - requests are blocked until categorization is complete
Implied Rules
Logging implied rules is recommended only to troubleshoot connectivity or VPN issues as it adds overhead to the gateway and management.
Hit Count Database
There are many rules that have not been hit in the last 3 months. Only required access to be allowed through the gateway; if the rule is not in use then it is not required.
Cluster1 Cluster Review
The following findings have been identified on the R80.10 VSec cluster:
| Topic | Status | Recommendations |
|---|---|---|
| Hotfix | X | Gateway vulnerability to be remediated with latest JHF. |
| NAT Cache | i | |
| Misplaced Rules | A | Performance can be improved by moving rules within the policy. |
| VOIP | A | Firewall Early NAT chain enabled but no VOIP traffic passing gateway. |
| Snapshot/Backup | A | No backups scheduled. |
| AAA | A | Local accounts only defined. |
| Interface buffers | X | Inconsistent values set. |
| Fragments | A | Determine source of fragments. |
| Sync | X | Sync issues detected. |
| Zombie Processes | X | 5 zombie processes detected. |
| Weak Ciphers | A | Default ciphers configured. |
| SNMP Version | X | Insecure version of SNMP configured. |
| HA State | A | Recent change of state. |
| Logging | A | Non-resilient logging. |
| Anti-Spoofing | X | Not configured correctly. |
| Drop Templates | A | Optimization possible. |
| NTP | X | Version configured open to exploit. |
| ARP | X | sk18463 |
| Stealth | X | Missing. |
Hotfix
R80.10 Jumbo Hotfix Accumulator is an accumulation of stability and quality fixes resolving multiple issues in different products.
NAT Cache
NAT Cache limit has exceeded. This will not cause any problems, as these connections will be matched against the NAT rules instead of the NAT cache table.
Misplaced Rules
Review the policy and move rules with the highest hit count as far to the top of the policy as possible.
Snapshot/Backup
There are no Snapshots, Backups or Scheduled Backups on the system.
AAA
AAA is used to authorize, authenticate and account user access. Only local user accounts are configured on the gateway:
Weak Ciphers
Weak Ciphers are allowed to and through the gateway. If in a PCI environment then they need to be hard disabled, if not then they can be prevented in security and IPS policy.
Sync
High delay in sync traffic reported with minimal out of RX-Drp and RX-Ovr on the Sync interface.
ARP
Detects recent errors. Review physical connections as needed.
NTP
NTP versions 1-3 are no longer maintained, delays in security may occur.
Consultant Overview
The main concern in the environment is security; gateways susceptible to vulnerabilities, no stealth rules, insecure versions of SNMP and NTP in use. Access to VS 0 not logged and open to “Any” source, non-resilient logging/auditing, no AAA measure available.
On the plus side, the systems are not under any particular load. Check Point PS would recommend utilizing this resource to enable HTTPS Inspection to enhance perimeter security.
Overall, systems perform well and have resources available for further enhancements but should address identified issues immediately for stability and security.
Disclaimer
The Customer hereby attests and acknowledges that the Check Point Professional Services Engineer has completed the project work described. This work meets the requirements specified by the Customer and has been completed to the satisfaction of the Customer.