tracker
Snapshot and /boot disk space full
@HeikoAnkenbrand you started a good post; I usually do snapshots, but before every update, I check if there are any snapshots available, I delete all the snapshots, and I create a new snapshot.
Usually, I keep always one snapshot on the firewall (the latest before the upgrade), because, if I have issue with the upgrade only the latest snapshot is useful, in my opinion reverting to older snapshot shouldn't happen.
OpenAI Shares Unprecedented AI Cybersecurity Incident
Yes, it's beyond every sci-fi movies.
@israelfds95 I like your post, and I agree with you.
World, and security, are changing faster than expected.
Hardware Recommendation Report in Web SmartConsole - SK185102 - What's New
You're right ... I changed the headline.
I noticed only because when I opened Smartconsole, a banner in the upper part of the window appeared reporting that the Hardware recommendation report is available.
Hardening Recommendation Report in Web SmartConsole - SK185102 - What's New
Hello All
let me post this SK:
https://support.checkpoint.com/results/sk/sk185102
The SK deals with the creation of a Hardening Security Report about compliance in policies and gateways, suggesting also recommendations to increase security.
I found it interesting to share it, maybe most of the Check Mates people know it.
ldap communication has stop to work
If you can use LDAP in clear text, try to perform a capture with tcpdump between management server and LDAP server, so it will be possible to verify possible issues.
Why do we need Zero Trust today more than ever before?
Thanks @Peter_Elmer ... great videos.
Some sites not working with HTTPS Inspection enabled
I agree with you, it could also something like WAF, or similar that we don't know.
At the moment, for me it's inexplicable, and at the moment I can't test it on my side.
Could you also provide the regexp for the site you want to reach? Just for curiosity.
And how did you configured the rule that is using Custom Application? Maybe there something that can be adjusted in the custom application (maybe).
checking DNS resolution for your site I found this:
Nome: www.ceair.com.wswebcdn.com
Address: 157.185.129.11
Aliases: www.ceair.com
This was the IP address configured in destination field for the bypass rule?
If yes, there is no reason to explain why in your case, bypass worked only configuring the rule with your PC in source field; what if, you add the IP address of the site in the destination field in the working rule? Is it matched? Is it working?
You shouldn't find dropped packets; the bypass rule configured by adding the destination IP address of the site should work, unless the site you're connecting is performing any redirect to any other FQDN, or is trying to load some component from different site, and in this case, the SSL inspection is impacting the access to this resources that is not the main site you're requesting.
Maybe in this case, using the developer tools of the browser should give some information about the site/resources requested.
PAM
But I suppose you can store admin credential in your PAM solution, and when the user logs into PAM, when it connects to the firewall the admin credentials are used.
What is your needs about PAM?
To better understand, the rule that worked was configured setting you PC in source filed, and letting ANY in destination field?
could you explain better which kind of bypass you've configured (both working and not working rule)?
Did you check the content of file wstlsd.elg?
If you wish to perform a debug about HTTPS inspection you could refer to this SK: https://support.checkpoint.com/results/sk/sk105559
Five Habits That Improved My Check Point Deployments
I agree with you @israelfds95, what you wrote is probably the best way to work, unfortunately, for my experience, most of the time this approach is far from the reality, where the customer considers the installation of a firewall comparable to installing a PC.
I like to prepare and plan every job before pressing the keys on the keyboard, and I think that all the five steps are the right way to work.
External IOC Feed Alerts
I think it's not possible, unless you have some monitoring tool (like PRTG, ZABBIX, etc) and configure this monitoring tool to check URL availability.
Policy load at boot
It will load a local copy of "policy-from-cma".