smartoptimize sample report.pdf

CHECK POINT PROFESSIONAL SERVICES

Check Point SmartOptimize Report

Prepared for

By

Date


Executive Summary

The following document presents the result of a policy optimization project performed by Check Point. The project examined the deployment of your Check Point solutions and identified opportunities to optimize your network security management system. Check Point analysts used various utilities that assess the usage of the security policy, its optimization potential, and weaknesses. Combined with expert human analysis, the document identifies opportunities to improve overall management, gateway performance, and security.

Each recommendation is rated as follows:

System Health

Monitoring the system health of your Check Point solutions is critical to identify health issues before they affect system resources. The table below provides a summary on the system health of your management server.

Status Comments
Disk Usage
Memory Usage
License
Contract X 2 out of 4 contracts are expired.
Policies Assigned ! 3 out of 6 policies are not assigned.
Service Analysis ! Some of the services are not using their default timeouts. For more details refer to System Report.

Objects Database

The objects database size can affect performance and policy installation time. The table below provides a summary of the network objects database.

Status Count Percent Remediation
Total Network Objects 45786 100%
Unused Network Objects 4 0.01%
Duplicate Network Objects X 6456 14.1% Consider deleting copies.
Nested Network Objects 395 0.86%

Services Database

The services database size can affect performance and policy installation time. The table below provides a summary of the services objects database.

Status Count Percent Remediation
Total Services Objects 1375 100%
Unused Services Objects ⚠️ 46 3.35% Consider deleting these objects.
Nested Services Objects 7 0.51%

Rulebase Analysis

Policy Optimization Overview

The tables below provides general information about the current status of the active policies analyzed.

Status Count Percent Remediation
Total Rules 77 100%
Rules utilizing "Any" X 21 27.27% -ANY in Source:5-ANY in Destination:14-ANY in Service:2
Disabled Rules 3 3.9% Check if rules are required.
Unnamed Rules 30 38.96% Naming rules helps log analysis.
Times Rules 0 0%
Non-Logging Rules 20 25.97% Log rules for better rules tracking.

RuleBase Risk Analysis and Best Practices

Rulebase tends to grow over time and change requests, and the tables below summarize the optimization potential our experts have found in your active policies.

Stealth Rule Not Found
Cleanup Rule Found
Uncommented Rules 6 7.79% Comment rules for better tracking and change management compliance.
Section Titles 20 20 section titles found.
Optimization Potential 1 1.35%

Policy Hit-Count Overview

The tables below provide information about the misplaced rules in the active policies across all security layers.

Rules Hit Top Hit Rules Misplaced Rules Zero Hit Rules
Global Policy 72 6 5 12
Database Policy Layer 1 0 0 1
DMZ-VSX-policy Security 4 1 0 0

Policy: DMZ1-policy

Status Count Percent Remediation
Total Rules 190 100%
Rules utilizing "Any" X 39 20.53% -ANY in Source:13-ANY in Destination:21-ANY in Service:5
Disabled Rules 4 2.11% Check if rules are required.
Unnamed Rules 123 64.74% Naming rules helps log analysis.
Times Rules 0 0%
Non-Logging Rules 23 12.11% Log rules for better rules tracking.
Stealth Rule X Not Found
Cleanup Rule Found
Uncommented Rules 3 1.58% Comment rules for better tracking and change management compliance.
Section Titles 49 49 section titles found.
Optimization Potential 10 5.35%

Policy: DMZ2-policy

Status Count Percent Remediation
Total Rules 123 100%
Rules utilizing "Any" X 30 24.39% -ANY in Source:8-ANY in Destination:18-ANY in Service:4
Disabled Rules 21 17.07% Check if rules are required.
Unnamed Rules 65 52.85% Naming rules helps log analysis.
Times Rules 0 0%
Non-Logging Rules 23 18.7% Log rules for better rules tracking.
Stealth Rule X Not Found
Cleanup Rule Found
Uncommented Rules 7 5.69% Comment rules for better tracking and change management compliance.
Section Titles 31 31 section titles found.
Optimization Potential 2 1.65%

Consultant Comments

Findings

Thanks to Jon P for the template.

This SmartOptimize service took an export of the XYZ Check Point management station and submitted it for review by Check Point Professional Services. This document is the result of that analysis and will help XYZ to provide maximum protection for their information assets, employees, and Governance / Risk and Compliance (GRC) auditing.

The general feedback is that the Check Point configuration is adequate, but improvements must be made to reach the standard of "best practice".

The transformation could take several weeks of effort. Check Point Professional Services can support XYZ through this transition and ensure that the Check Point installed products are optimally utilized.


Remediation Recommendations

System Health
Contract Remediation
Contracts complete licenses and are the support availability behind every product you own. These contracts signify your ability to receive support, and are stored in encrypted text files on your management station. They might be required for certain maintenance and/or upgrade operations. If your contracts files are not valid, expired, or not installed, please follow the steps in the "Health check" section to remediate the problem.
Users Remediation
Local users are defined when internal authentication is used with remote VPN and other functionalities. These users are stored encrypted in fwauth.NDB file and are important to the proper usage of VPN in your system. Too many users can cause overhead, so redundant ones should be removed. Please follow instructions related to users cleanup and or activities in the "health check section".
Anti-Spoofing Remediation
"Spoofing" is when an attacker is masking their IP address to appear as if it’s another, mostly from an internal/trusted network to bypass security devices. "Anti-Spoofing" is a security mechanism by Check Point that allows identifying such attempts easily based on the GW's topology. Check Point recommends enabling "Anti-spoofing" by configuring the topology properly on all GWs using static routing configurations. Please refer to "SystemInfo" document to see a list of incompatible security GWs.
Global Properties Remediation
Global Properties are a set of rules and configurations that are valid throughout the system and configured centrally; these include some security features that affect system-wide. Accessing these properties is available from "Policy" -> "Global Properties". Check Point recommends reviewing the items found in our analysis, as appearing in "SystemInfo" document.
Policy Optimization
Rulebase Size Remediation
Rulebase size is the finite number of rules in an active policy, including active, unused, and disabled rules. Policy size is also a key factor in the policy installation time (compilation).
Check Point recommends having the rulebase size in the final number of a few hundred at most; it’s clear that a smaller rulebase is not only easier to manage and administer but also has less risk of potential security breaches or redundant rules. Please follow the steps related to this section to reduce the size of your rulebase accordingly.

Basic Risk Analysis

Rulebase Utilizing "Any"

"Any" is an option that can be used in the rulebase as a generic option for source, destination, or service. However, this is not a secure manner of usage in rules, as it might allow unauthorized access and/or usage of services.

Remediation

Check Point recommends minimizing the use of "Any" in rules, especially in rules that allow traffic to or from the WAN. Please refer to "RuleBaseReport" document for more details.

Disabled Rules

Disabled rules are rules that are part of the management database but do not transfer to the GW as part of its policy. These rules are probably not needed due to their expiration or irrelevancy over time.

Remediation

Check Point recommends observing the Disabled rules and "marking" them for deletion. Delete the rules after you have certainty that they are not used. You can use the "unused logged rules" to verify that if these rules are also logged.

Unused Logged Rules

Unused rules are mostly leftovers from past change requests and change in administrators that didn't have the ability or knowledge to delete them. Those rules pose an unnecessary burden on the active policy in terms of administration and indirect impact on performance.

Remediation

Check Point recommends placing unused rules in "monitor" status, by disabling them and setting an ultimatum for their deletion, then delete them after the monitoring period. Please see "RuleBaseReport" document.


Disclaimer

The Customer hereby attests and acknowledges that the Check Point Professional Services Engineer has completed the project work described above. This work meets the requirements specified by the Customer and has been completed to the satisfaction of the Customer.

By: Authorized Customer Representative
By: Check Point Professional Services Representative
Date:
Date:


Post Project Contact Information

Technical Issues

Check Point Software offers a variety of assistance methods for their customers. Check Point Software provides direct customer support through our Worldwide Technical Assistance Centers for customers who purchase a support contract. Customers may also purchase follow-up telephone assistance from Professional Services. Alternatively, a customer may work with a local Check Point reseller for support.

Check Point Professional Services

We offer follow-up telephone support at the rate of $800 per ½ day. Please contact us for this or any future Professional Services project needs.
E-mail: ps@checkpoint.com
Phone: +972-3-7534796

Check Point Technical Support

Our Worldwide Technical Assistance Centers are available to assist you 24x7.

Please provide your organization's support number when contacting Technical Services.

Check Point Sales

To find a Check Point Reseller:
Phone: 1-800-429-4391
E-mail: sales@checkpoint.com
Web: http://www.checkpoint.com/sales/index.html

© 2022 Check Point Software Technologies Ltd. All rights reserved.
Classification: [Customer Confidential] — For customer use only