# CHECK POINT PROFESSIONAL SERVICES

## Check Point SmartOptimize Report

Prepared for  
<Customer ACME>

By  
<PS Consultant>

Date  
<Date>

---

## Executive Summary

The following document presents the result of a policy optimization project performed by Check Point. The project examined the deployment of your Check Point solutions and identified opportunities to optimize your network security management system. Check Point analysts used various utilities that assess the usage of the security policy, its optimization potential, and weaknesses. Combined with expert human analysis, the document identifies opportunities to improve overall management, gateway performance, and security.

### Each recommendation is rated as follows:
- **Serious:** Needs immediate attention (8 Items)
- **Attention:** Needs attention (15 Items)
- **Good:** No need for any action (23 Items)

## System Health

Monitoring the system health of your Check Point solutions is critical to identify health issues before they affect system resources. The table below provides a summary on the system health of your management server.

|  | Status | Comments |
| --- | --- | --- |
| Disk Usage | √ |  |
| Memory Usage | √ |  |
| License | √ |  |
| Contract | X | 2 out of 4 contracts are expired. |
| Policies Assigned | ! | 3 out of 6 policies are not assigned. |
| Service Analysis | ! | Some of the services are not using their default timeouts. For more details refer to System Report. |

---

## Objects Database

The objects database size can affect performance and policy installation time. The table below provides a summary of the network objects database.

|  | Status | Count | Percent | Remediation |
| --- | --- | --- | --- | --- |
| Total Network Objects | √ | 45786 | 100% |  |
| Unused Network Objects | √ | 4 | 0.01% |  |
| Duplicate Network Objects | X | 6456 | 14.1% | Consider deleting copies. |
| Nested Network Objects | √ | 395 | 0.86% |  |

## Services Database

The services database size can affect performance and policy installation time. The table below provides a summary of the services objects database.

|  | Status | Count | Percent | Remediation |
| --- | --- | --- | --- | --- |
| Total Services Objects | √ | 1375 | 100% |  |
| Unused Services Objects | ⚠️ | 46 | 3.35% | Consider deleting these objects. |
| Nested Services Objects | √ | 7 | 0.51% |  |

## Rulebase Analysis

### Policy Optimization Overview

The tables below provides general information about the current status of the active policies analyzed.

|  | Status | Count | Percent | Remediation |
| --- | --- | --- | --- | --- |
| Total Rules | √ | 77 | 100% |  |
| Rules utilizing "Any" | X | 21 | 27.27% | -ANY in Source:5-ANY in Destination:14-ANY in Service:2 |
| Disabled Rules | Ⓧ | 3 | 3.9% | Check if rules are required. |
| Unnamed Rules | Ⓧ | 30 | 38.96% | Naming rules helps log analysis. |
| Times Rules | ✓ | 0 | 0% |  |
| Non-Logging Rules | Ⓧ | 20 | 25.97% | Log rules for better rules tracking. |

### RuleBase Risk Analysis and Best Practices

Rulebase tends to grow over time and change requests, and the tables below summarize the optimization potential our experts have found in your active policies.

| Stealth Rule |  |  |  | Not Found |
| --- | --- | --- | --- | --- |
| Cleanup Rule |  |  |  | Found |
| Uncommented Rules |  | 6 | 7.79% | Comment rules for better tracking and change management compliance. |
| Section Titles |  | 20 |  | 20 section titles found. |
| Optimization Potential |  | 1 | 1.35% |  |

### Policy Hit-Count Overview

The tables below provide information about the misplaced rules in the active policies across all security layers.

|  | Rules Hit | Top Hit Rules | Misplaced Rules | Zero Hit Rules |
| --- | --- | --- | --- | --- |
| Global Policy | 72 | 6 | 5 | 12 |
| Database Policy Layer | 1 | 0 | 0 | 1 |
| DMZ-VSX-policy Security | 4 | 1 | 0 | 0 |

### Policy: DMZ1-policy

|  | Status | Count | Percent | Remediation |
| --- | --- | --- | --- | --- |
| Total Rules | √ | 190 | 100% |  |
| Rules utilizing "Any" | X | 39 | 20.53% | -ANY in Source:13-ANY in Destination:21-ANY in Service:5 |
| Disabled Rules | Ⓧ | 4 | 2.11% | Check if rules are required. |
| Unnamed Rules | Ⓧ | 123 | 64.74% | Naming rules helps log analysis. |
| Times Rules | √ | 0 | 0% |  |
| Non-Logging Rules | Ⓧ | 23 | 12.11% | Log rules for better rules tracking. |
| Stealth Rule | X |  |  | Not Found |
| Cleanup Rule | √ |  |  | Found |
| Uncommented Rules | Ⓧ | 3 | 1.58% | Comment rules for better tracking and change management compliance. |
| Section Titles | √ | 49 |  | 49 section titles found. |
| Optimization Potential | √ | 10 | 5.35% |  |

### Policy: DMZ2-policy

|  | Status | Count | Percent | Remediation |
| --- | --- | --- | --- | --- |
| Total Rules | √ | 123 | 100% |  |
| Rules utilizing "Any" | X | 30 | 24.39% | -ANY in Source:8-ANY in Destination:18-ANY in Service:4 |
| Disabled Rules | Ⓧ | 21 | 17.07% | Check if rules are required. |
| Unnamed Rules | Ⓧ | 65 | 52.85% | Naming rules helps log analysis. |
| Times Rules | √ | 0 | 0% |  |
| Non-Logging Rules | Ⓧ | 23 | 18.7% | Log rules for better rules tracking. |
| Stealth Rule | X |  |  | Not Found |
| Cleanup Rule | √ |  |  | Found |
| Uncommented Rules | Ⓧ | 7 | 5.69% | Comment rules for better tracking and change management compliance. |
| Section Titles | √ | 31 |  | 31 section titles found. |
| Optimization Potential | √ | 2 | 1.65% |  |

## Consultant Comments

### Findings

Thanks to Jon P for the template.

This SmartOptimize service took an export of the XYZ Check Point management station and submitted it for review by Check Point Professional Services. This document is the result of that analysis and will help XYZ to provide maximum protection for their information assets, employees, and Governance / Risk and Compliance (GRC) auditing.

The general feedback is that the Check Point configuration is adequate, but improvements must be made to reach the standard of "best practice".

The transformation could take several weeks of effort. Check Point Professional Services can support XYZ through this transition and ensure that the Check Point installed products are optimally utilized.

---

## Remediation Recommendations

| System Health |  |
| --- | --- |
| Contract | Remediation |
| Contracts complete licenses and are the support availability behind every product you own. These contracts signify your ability to receive support, and are stored in encrypted text files on your management station. They might be required for certain maintenance and/or upgrade operations. | If your contracts files are not valid, expired, or not installed, please follow the steps in the "Health check" section to remediate the problem. |
| Users | Remediation |
| Local users are defined when internal authentication is used with remote VPN and other functionalities. These users are stored encrypted in fwauth.NDB file and are important to the proper usage of VPN in your system. Too many users can cause overhead, so redundant ones should be removed. | Please follow instructions related to users cleanup and or activities in the "health check section". |
| Anti-Spoofing | Remediation |
| "Spoofing" is when an attacker is masking their IP address to appear as if it’s another, mostly from an internal/trusted network to bypass security devices. "Anti-Spoofing" is a security mechanism by Check Point that allows identifying such attempts easily based on the GW's topology. | Check Point recommends enabling "Anti-spoofing" by configuring the topology properly on all GWs using static routing configurations. Please refer to "SystemInfo" document to see a list of incompatible security GWs. |
| Global Properties | Remediation |
| Global Properties are a set of rules and configurations that are valid throughout the system and configured centrally; these include some security features that affect system-wide. Accessing these properties is available from "Policy" -> "Global Properties". | Check Point recommends reviewing the items found in our analysis, as appearing in "SystemInfo" document. |
| Policy Optimization |  |
| Rulebase Size | Remediation |
| Rulebase size is the finite number of rules in an active policy, including active, unused, and disabled rules. Policy size is also a key factor in the policy installation time (compilation).
| Check Point recommends having the rulebase size in the final number of a few hundred at most; it’s clear that a smaller rulebase is not only easier to manage and administer but also has less risk of potential security breaches or redundant rules. Please follow the steps related to this section to reduce the size of your rulebase accordingly. |

---

## Basic Risk Analysis

### Rulebase Utilizing "Any"

"Any" is an option that can be used in the rulebase as a generic option for source, destination, or service. However, this is not a secure manner of usage in rules, as it might allow unauthorized access and/or usage of services.

### Remediation

Check Point recommends minimizing the use of "Any" in rules, especially in rules that allow traffic to or from the WAN. Please refer to "RuleBaseReport" document for more details.

### Disabled Rules

Disabled rules are rules that are part of the management database but do not transfer to the GW as part of its policy. These rules are probably not needed due to their expiration or irrelevancy over time.

### Remediation

Check Point recommends observing the Disabled rules and "marking" them for deletion. Delete the rules after you have certainty that they are not used. You can use the "unused logged rules" to verify that if these rules are also logged.

### Unused Logged Rules

Unused rules are mostly leftovers from past change requests and change in administrators that didn't have the ability or knowledge to delete them. Those rules pose an unnecessary burden on the active policy in terms of administration and indirect impact on performance.

### Remediation

Check Point recommends placing unused rules in "monitor" status, by disabling them and setting an ultimatum for their deletion, then delete them after the monitoring period. Please see "RuleBaseReport" document.

---

### Disclaimer

The Customer hereby attests and acknowledges that the Check Point Professional Services Engineer has completed the project work described above. This work meets the requirements specified by the Customer and has been completed to the satisfaction of the Customer.

By: Authorized Customer Representative  
By: <NAME> Check Point Professional Services Representative  
Date:  
Date: <DATE>

---

## Post Project Contact Information

### Technical Issues

Check Point Software offers a variety of assistance methods for their customers. Check Point Software provides direct customer support through our Worldwide Technical Assistance Centers for customers who purchase a support contract. Customers may also purchase follow-up telephone assistance from Professional Services. Alternatively, a customer may work with a local Check Point reseller for support.

### Check Point Professional Services

We offer follow-up telephone support at the rate of $800 per ½ day. Please contact us for this or any future Professional Services project needs.  
E-mail: ps@checkpoint.com  
Phone: +972-3-7534796

### Check Point Technical Support

Our Worldwide Technical Assistance Centers are available to assist you 24x7.

- **Americas:** 972-444-6600  
- **International (Non-US):** +972-3-6115100  
E-mail: support@ts.checkpoint.com  
Web: http://support.checkpoint.com

Please provide your organization's support number when contacting Technical Services.

### Check Point Sales

To find a Check Point Reseller:  
Phone: 1-800-429-4391  
E-mail: sales@checkpoint.com  
Web: http://www.checkpoint.com/sales/index.html

© 2022 Check Point Software Technologies Ltd. All rights reserved.  
Classification: [Customer Confidential] — For customer use only
