Gateway HealthCheck Sample Report

Check Point Gateway Health Check Report

Prepared for

By

Date


Executive Summary

Check Point Professional Services have been engaged to run a Health Check to ensure the following devices are installed to Check Point best practices and optimized.

Hardware Name Cluster Version Jumbo

  • VMware Virtual Platform fw1-management R80.10 Take 91
  • VMware Virtual Platform FW1 Cluster1 R80.10 Take 112
  • VMware Virtual Platform FW2 Cluster1 R80.10 Take 112
  • Check Point 23800 vsx-1 VSXCluster2 R80.10 Take 103
  • Check Point 23800 vsx-2 VSXCluster2 R80.10 Take 103

The Health Check includes Summary Reports, Health Check Reports and any supporting documentation. This Consultant Report will summarize the findings and highlight any concerns or recommendations.

have also requested a review on network design.


Management Review

The following findings have been identified on the R80.10 Security Management Server (fw1-management):

Topic Status Recommendations
Hotfix X Old version of JHF installed with known issues.
Licenses & Contracts ▲ Number of expired licenses and contracts.
Object Database X High amount of unused and duplicate objects.
Unassigned Policies ▲ 50% of policies are unassigned + increasing object count.
Session Timeout ▲ Default values increased.
Out of State X TCP out of state allowed. Security concern.
Disk Usage ▲ 85% disk usage.
Memory Usage i Swapping.
CPU Usage i Above expected value.
Local Users ▲ Improvement to prevent unauthorized access.
SNMP X Disabled.
IPS – Server Config ▲ Servers not defined.
Blade Updates ▲ Incorrect warnings.
Online Web Service ▲ Set to Background.
Implied Rules ▲ Logging implied rules.
Hit Count Database ▲ Many unused rules.

Professional Services

Hotfix

R80.10 Jumbo Hotfix Accumulator is an accumulation of stability and quality fixes resolving multiple issues in different products.

A backup taken from the installed take 91 will not restore correctly. Sk123352

Recommended to install the latest jumbo to enhance feature set and improve stability.

Licenses and Contracts

The license repository contains a number of expired licenses and contracts.

| License | 3 out of 27 licenses are expired. | | Contract | 14 out of 51 contracts are expired. |

Object Database

The environment has a high number of duplicate and unused objects. The high number of duplicate objects is a concern; on policy push all used objects are verified. Remediating the duplicate objects would greatly improve policy push times.

Status Count Percent Remediation
Total Network Objects ✅ 4638 100%
Unused Network Objects ✘ 966 20.83% Consider deleting these objects.
Duplicate Network Objects ✘ 3162 68.18% Consider deleting copies.
Nested Network Objects ✅ 41 0.88%
Total Services Objects ✅ 1283 100%
Unused Services Objects ✘ 208 16.21% Consider deleting these objects.
Nested Services Objects ✅ 26 2.03%

A separate object report will be provided to identify duplicate and unused objects.

Unassigned Policies

Removing the unassigned policies eliminates the possibility for human error but more importantly, increases the amount of unused objects and allows a greater potential for object database cleanup.

Policies Assigned
5 out of 10 policies are not assigned.

Session Timeouts

The default timeouts have been changed. Extending the session timeouts increases the gateway connection table utilizing additional memory.

Values Default Session Timeouts
TCP start timeout: 60 seconds TCP start timeout: 25 seconds
TCP session timeout: 1800 seconds TCP session timeout: 3600 seconds
TCP end timeout: 50 seconds TCP end timeout: 20 seconds
UDP virtual session timeout: 90 seconds UDP virtual session timeout: 40 seconds
ICMP virtual session timeout: 30 seconds ICMP virtual session timeout: 30 seconds
Other IP protocols virtual session timeout: 60 seconds Other IP protocols virtual session timeout: 60 seconds
SCTP start timeout: 30 seconds SCTP start timeout: 30 seconds
SCTP session timeout: 3600 seconds SCTP session timeout: 3600 seconds
SCTP end timeout: 20 seconds SCTP end timeout: 20 seconds

Out of State

TCP out of state packets are allowed for all gateways. Allowing out of state packets allows the potential of a Denial of Service attack to all protected servers.

Highly recommended to prevent out of state packets; especially as the reviewed gateways are on the internet perimeter.

Disk Usage

Log directory at 85% usage:

Filesystem Type Size Used Avail Use% Mounted on
/dev/mapper/vg_splat-lv_current ext3 47G 16G 29G 37% /
proc proc 0 0 0 - /proc
sysfs sysfs 0 0 0 - /sys
devpts devpts 0 0 0 - /dev/pts
/dev/sda1 ext3 289M 24M 251M 9% /boot
tmpfs tmpfs 16G 4.0K 16G 1% /dev/shm
/dev/mapper/vg_splat-lv_log ext3 97G 78G 15G 85% /var/log

There are some large files that could be removed to increase available space:

[Expert@fwl-management:0]# find / -size +500M
/home/admin/fwl-management_3_9_2018_13_07_migrate_export_out.tgz
/home/admin/fwl-management_8_5_2018_15_06_migrate_export_out.tgz
/var/log/CPackup/bachups/6_0c_18_16_migate-export.tgz
/var/log/CPRA/repository/CheckPointCPRUpdatee#All#6.0####BUNDLE_R80_10_JUMBO_HF#91/Check_Point_R80_
10_JUMBO_HF_Bundle_791_sk116380_FULL.tgz
/var/log/dump/usermode/fvm.4293.core.gz

Memory Usage

The system currently has sufficient memory; but prior to the 3rd September memory usage was at around 100%.

Current usage:

total used free shared buffers cached
32823288 31546036 1277252 0 1078096 11319580
+/ buffers/cache: 19148360 13674928
Swap 39551744 120 39551624
Total 66375032 31546156 34828876

CPU Usage

CPU usage is within acceptable values, but as it’s a VM an additional CPU or two would improve the user experience.

%user %nice %system %iowait %steal %idle
18.45 2.18 2.28 0.93 0.00 76.10
20.51 2.41 2.69 1.64 0.00 72.70
16.39 1.96 1.87 0.23 0.00 79.50
17.06 0.70 1.87 0.75 0.00 79.60
18.46 0.66 2.21 1.27 0.00 77.40
15.67 0.74 1.52 0.23 0.00 81.80
17.16 0.73 1.86 0.74 0.00 79.50
18.15 0.71 2.15 1.27 0.00 77.70
16.18 0.75 1.56 0.21 0.00 81.30
16.86 0.88 1.82 0.69 0.00 79.70

Local Users

Both CLI and SmartConsole have users defined with local accounts only. It is recommended to configure AAA; so when users leave the company and removed from Active Directory they are automatically restricted access.

Name Expiration Date Profile Authentication Method
admin Dec 31,2030 Super User OS Password
Dec 31,2018 Super User Check Point Password
Dec 31,2018 read_write Check Point Password
Dec 31,2030 read_write Check Point Password
Dec 31,2020 read_write Check Point Password
Jan 31,2020 read_write Check Point Password

It would also be recommended to enable a lockout policy on both CLI and GUI to prevent any Brute Force Authentication attacks.

SNMP

SNMP is used to monitor the system and identify any potential issues. SNMP agent is disabled.

General Info SNMP Agent Disabled
SNMP Agent Disabled

IPS - Server Configuration

Some IPS protections are only applied against defined servers. Web, Mail and DNS servers need to be defined in the host objects for these IPS protections to take effect.

Logging

Logs are set to only be sent to a single log server. In the instance where the logserver is not reachable the configuration could be set to send logs to the management rather than log locally.

Anti-Spoofing

Anti-spoofing is the first line of defense from unauthorized access attempts and ensure the firewall policy is correctly applied as Check Point enforce a policy based security policy (rather than zone-based).

Check Point recommend to configure Anti-Spoofing correctly.

Drop Templates

There are a lot of drop rules in the policy with high connection hits. Enabling Drop templates would improve acceleration statistics, gateway performance and connection latency; but the gateway doesn’t currently have a performance issue and does not need the optimization; but the option is available.

NTP

NTP versions 1-3 are no longer maintained, so any security flaws uncovered are not patched and remain dangerously exploitable. There are many NTP exploits so using the latest version is highly recommended:

set ntp active on
set ntp server primary no.pool.ntp.org version 1

Consultant Overview

The main concern in the environment is security; due to gateways susceptible to SegmentSmack vulnerability, no stealth rules, insecure versions of SNMP and NTP in use, many rules defined that are not in use/required, access to VS 0 not logged and open to "Any" source, non-resilient logging/auditing, no AAA to determine who accessed the system etc (as highlighted in this document).

On the plus side, the systems are not under any particular load. Check Point PS would recommend utilizing this resource to enable HTTPS Inspection to enhance the perimeters security.

Overall, the systems are performing well and have the resources to enable further blades/features to improve securing the environment; but there are some identified issues that should be remediated as soon as possible to improve stability and security.


Disclaimer

The Customer hereby attests and acknowledges that the Check Point Professional Services Engineer has completed the project work described above. This work meets the requirements specified by the Customer and has been completed to the satisfaction of the Customer.