Gateway HealthCheck Sample Report
Check Point Gateway Health Check Report
Prepared for
By
Date
Executive Summary
Check Point Professional Services have been engaged to run a Health Check to ensure the following devices are installed to Check Point best practices and optimized.
Hardware Name Cluster Version Jumbo
- VMware Virtual Platform fw1-management R80.10 Take 91
- VMware Virtual Platform FW1 Cluster1 R80.10 Take 112
- VMware Virtual Platform FW2 Cluster1 R80.10 Take 112
- Check Point 23800 vsx-1 VSXCluster2 R80.10 Take 103
- Check Point 23800 vsx-2 VSXCluster2 R80.10 Take 103
The Health Check includes Summary Reports, Health Check Reports and any supporting documentation. This Consultant Report will summarize the findings and highlight any concerns or recommendations.
Management Review
The following findings have been identified on the R80.10 Security Management Server (fw1-management):
| Topic | Status | Recommendations |
|---|---|---|
| Hotfix | X | Old version of JHF installed with known issues. |
| Licenses & Contracts | ▲ | Number of expired licenses and contracts. |
| Object Database | X | High amount of unused and duplicate objects. |
| Unassigned Policies | ▲ | 50% of policies are unassigned + increasing object count. |
| Session Timeout | ▲ | Default values increased. |
| Out of State | X | TCP out of state allowed. Security concern. |
| Disk Usage | ▲ | 85% disk usage. |
| Memory Usage | i | Swapping. |
| CPU Usage | i | Above expected value. |
| Local Users | ▲ | Improvement to prevent unauthorized access. |
| SNMP | X | Disabled. |
| IPS – Server Config | ▲ | Servers not defined. |
| Blade Updates | ▲ | Incorrect warnings. |
| Online Web Service | ▲ | Set to Background. |
| Implied Rules | ▲ | Logging implied rules. |
| Hit Count Database | ▲ | Many unused rules. |
Professional Services
Hotfix
R80.10 Jumbo Hotfix Accumulator is an accumulation of stability and quality fixes resolving multiple issues in different products.
A backup taken from the installed take 91 will not restore correctly. Sk123352
Recommended to install the latest jumbo to enhance feature set and improve stability.
Licenses and Contracts
The license repository contains a number of expired licenses and contracts.
| License | 3 out of 27 licenses are expired. | | Contract | 14 out of 51 contracts are expired. |
Object Database
The environment has a high number of duplicate and unused objects. The high number of duplicate objects is a concern; on policy push all used objects are verified. Remediating the duplicate objects would greatly improve policy push times.
| Status | Count | Percent | Remediation |
|---|---|---|---|
| Total Network Objects | ✅ | 4638 | 100% |
| Unused Network Objects | ✘ | 966 | 20.83% Consider deleting these objects. |
| Duplicate Network Objects | ✘ | 3162 | 68.18% Consider deleting copies. |
| Nested Network Objects | ✅ | 41 | 0.88% |
| Total Services Objects | ✅ | 1283 | 100% |
| Unused Services Objects | ✘ | 208 | 16.21% Consider deleting these objects. |
| Nested Services Objects | ✅ | 26 | 2.03% |
A separate object report will be provided to identify duplicate and unused objects.
Unassigned Policies
Removing the unassigned policies eliminates the possibility for human error but more importantly, increases the amount of unused objects and allows a greater potential for object database cleanup.
| Policies | Assigned |
|---|---|
| 5 out of 10 policies are not assigned. |
Session Timeouts
The default timeouts have been changed. Extending the session timeouts increases the gateway connection table utilizing additional memory.
| Default Session Timeouts | |
|---|---|
| TCP start timeout: 60 seconds | TCP start timeout: 25 seconds |
| TCP session timeout: 1800 seconds | TCP session timeout: 3600 seconds |
| TCP end timeout: 50 seconds | TCP end timeout: 20 seconds |
| UDP virtual session timeout: 90 seconds | UDP virtual session timeout: 40 seconds |
| ICMP virtual session timeout: 30 seconds | ICMP virtual session timeout: 30 seconds |
| Other IP protocols virtual session timeout: 60 seconds | Other IP protocols virtual session timeout: 60 seconds |
| SCTP start timeout: 30 seconds | SCTP start timeout: 30 seconds |
| SCTP session timeout: 3600 seconds | SCTP session timeout: 3600 seconds |
| SCTP end timeout: 20 seconds | SCTP end timeout: 20 seconds |
Out of State
TCP out of state packets are allowed for all gateways. Allowing out of state packets allows the potential of a Denial of Service attack to all protected servers.
Highly recommended to prevent out of state packets; especially as the reviewed gateways are on the internet perimeter.
Disk Usage
Log directory at 85% usage:
| Filesystem | Type | Size | Used | Avail | Use% | Mounted on |
|---|---|---|---|---|---|---|
| /dev/mapper/vg_splat-lv_current | ext3 | 47G | 16G | 29G | 37% | / |
| proc | proc | 0 | 0 | 0 | - | /proc |
| sysfs | sysfs | 0 | 0 | 0 | - | /sys |
| devpts | devpts | 0 | 0 | 0 | - | /dev/pts |
| /dev/sda1 | ext3 | 289M | 24M | 251M | 9% | /boot |
| tmpfs | tmpfs | 16G | 4.0K | 16G | 1% | /dev/shm |
| /dev/mapper/vg_splat-lv_log | ext3 | 97G | 78G | 15G | 85% | /var/log |
There are some large files that could be removed to increase available space:
[Expert@fwl-management:0]# find / -size +500M
/home/admin/fwl-management_3_9_2018_13_07_migrate_export_out.tgz
/home/admin/fwl-management_8_5_2018_15_06_migrate_export_out.tgz
/var/log/CPackup/bachups/6_0c_18_16_migate-export.tgz
/var/log/CPRA/repository/CheckPointCPRUpdatee#All#6.0####BUNDLE_R80_10_JUMBO_HF#91/Check_Point_R80_
10_JUMBO_HF_Bundle_791_sk116380_FULL.tgz
/var/log/dump/usermode/fvm.4293.core.gz
Memory Usage
The system currently has sufficient memory; but prior to the 3rd September memory usage was at around 100%.
Current usage:
| total | used | free | shared | buffers | cached |
|---|---|---|---|---|---|
| 32823288 | 31546036 | 1277252 | 0 | 1078096 | 11319580 |
| +/ buffers/cache: | 19148360 | 13674928 | |||
| Swap | 39551744 | 120 | 39551624 | ||
| Total | 66375032 | 31546156 | 34828876 |
CPU Usage
CPU usage is within acceptable values, but as it’s a VM an additional CPU or two would improve the user experience.
| %user | %nice | %system | %iowait | %steal | %idle |
|---|---|---|---|---|---|
| 18.45 | 2.18 | 2.28 | 0.93 | 0.00 | 76.10 |
| 20.51 | 2.41 | 2.69 | 1.64 | 0.00 | 72.70 |
| 16.39 | 1.96 | 1.87 | 0.23 | 0.00 | 79.50 |
| 17.06 | 0.70 | 1.87 | 0.75 | 0.00 | 79.60 |
| 18.46 | 0.66 | 2.21 | 1.27 | 0.00 | 77.40 |
| 15.67 | 0.74 | 1.52 | 0.23 | 0.00 | 81.80 |
| 17.16 | 0.73 | 1.86 | 0.74 | 0.00 | 79.50 |
| 18.15 | 0.71 | 2.15 | 1.27 | 0.00 | 77.70 |
| 16.18 | 0.75 | 1.56 | 0.21 | 0.00 | 81.30 |
| 16.86 | 0.88 | 1.82 | 0.69 | 0.00 | 79.70 |
Local Users
Both CLI and SmartConsole have users defined with local accounts only. It is recommended to configure AAA; so when users leave the company and removed from Active Directory they are automatically restricted access.
| Name | Expiration Date | Profile | Authentication Method |
|---|---|---|---|
| admin | Dec 31,2030 | Super User | OS Password |
| Dec 31,2018 | Super User | Check Point Password | |
| Dec 31,2018 | read_write | Check Point Password | |
| Dec 31,2030 | read_write | Check Point Password | |
| Dec 31,2020 | read_write | Check Point Password | |
| Jan 31,2020 | read_write | Check Point Password |
It would also be recommended to enable a lockout policy on both CLI and GUI to prevent any Brute Force Authentication attacks.
SNMP
SNMP is used to monitor the system and identify any potential issues. SNMP agent is disabled.
| General Info | SNMP Agent Disabled |
|---|---|
| SNMP Agent | Disabled |
IPS - Server Configuration
Some IPS protections are only applied against defined servers. Web, Mail and DNS servers need to be defined in the host objects for these IPS protections to take effect.
Logging
Logs are set to only be sent to a single log server. In the instance where the logserver is not reachable the configuration could be set to send logs to the management rather than log locally.
Anti-Spoofing
Anti-spoofing is the first line of defense from unauthorized access attempts and ensure the firewall policy is correctly applied as Check Point enforce a policy based security policy (rather than zone-based).
Check Point recommend to configure Anti-Spoofing correctly.
Drop Templates
There are a lot of drop rules in the policy with high connection hits. Enabling Drop templates would improve acceleration statistics, gateway performance and connection latency; but the gateway doesn’t currently have a performance issue and does not need the optimization; but the option is available.
NTP
NTP versions 1-3 are no longer maintained, so any security flaws uncovered are not patched and remain dangerously exploitable. There are many NTP exploits so using the latest version is highly recommended:
set ntp active on
set ntp server primary no.pool.ntp.org version 1
Consultant Overview
The main concern in the environment is security; due to gateways susceptible to SegmentSmack vulnerability, no stealth rules, insecure versions of SNMP and NTP in use, many rules defined that are not in use/required, access to VS 0 not logged and open to "Any" source, non-resilient logging/auditing, no AAA to determine who accessed the system etc (as highlighted in this document).
On the plus side, the systems are not under any particular load. Check Point PS would recommend utilizing this resource to enable HTTPS Inspection to enhance the perimeters security.
Overall, the systems are performing well and have the resources to enable further blades/features to improve securing the environment; but there are some identified issues that should be remediated as soon as possible to improve stability and security.
Disclaimer
The Customer hereby attests and acknowledges that the Check Point Professional Services Engineer has completed the project work described above. This work meets the requirements specified by the Customer and has been completed to the satisfaction of the Customer.