Solved

snmp monitoring of Checkpoint firewall

Posted on 2014-10-28
10
379 Views
Last Modified: 2014-10-30
I have enabled SNMP on my checkpoint 4400 firewall running R77.10.  

However, I am not sure how to create a rule on the firewall to allow SNMP traffic to flow between my monitoring server (10.1.1.20) and the internal interface of the firewall (10.1.1.16).  I am new to Checkpoints so am a little lost.

SNMP-Rule.PNG
All of the documentation I have found online states that this needs to be done, but provides no instruction on how to do it.

Please help.
0
Comment
Question by:mtkaiser
  • 5
  • 4
10 Comments
 
LVL 62

Expert Comment

by:gheist
ID: 40410092
You need to allow from IP to IP and only SNMP
0
 
LVL 12

Accepted Solution

by:
Fidelius earned 250 total points
ID: 40410257
Your rule is OK. If you set up SNMP correctly, it should work.
You can clean up rule a little bit and leave only snmp and snmp-trap.

If you want more strict rule make it like this:
CP monitoring rule
And put the rule as high as possible, as it will be hit pretty often.
0
 
LVL 62

Assisted Solution

by:gheist
gheist earned 250 total points
ID: 40410370
No - snmp requests come from SNMP server and checkpoint keeps state to get responses back to SNMP server.
Then check logs (from one host to other host, looking for smart blocking errors, if yes, change rule to IP:any->CP:161 all UDP))

SNMP traps can notify monitoring system (if it includes SNMP trap handling), thats out of scope for first attempt. It will need a new rule in other direction 162/UDP, with same hand-patting to make it work.
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 
LVL 12

Expert Comment

by:Fidelius
ID: 40410441
Yes, I agree.
But if you put rule the way I wrote it, you will at the same time allow snmp queries from server to CheckPoint, and CheckPoint sending traps to server.
This rule can be separated in two rules, but if you put it like this, it is more clearer and easier to manage.
0
 
LVL 62

Expert Comment

by:gheist
ID: 40410447
But why to let unused protocols through?
0
 
LVL 12

Expert Comment

by:Fidelius
ID: 40410469
As I said, it is more clearer and easier to manage. Also it takes less resources on firewall upon compiling rules
If you want strict and very high level of security you can write two separate rules
- one allowing server to CP only at udp/161
- other allowing CP to server only for udp/162

At the end it is balance between security and manageability.
0
 
LVL 62

Expert Comment

by:gheist
ID: 40410477
In other words sacrificing of security on altar of laziness ;)
0
 
LVL 12

Expert Comment

by:Fidelius
ID: 40410492
It depends :)
Sometimes going to more restricted policies on inside network leads to more problems, especially if you have lots of rules, and lots of systems to manage. But this is totally different subject from one in question ;)
0
 
LVL 62

Expert Comment

by:gheist
ID: 40410509
My point is to check for conflicts with inspection engine at the very beginning to keep it running problem-free after.
0
 

Author Closing Comment

by:mtkaiser
ID: 40413709
Thanks guys!!
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Sonicwall will not export settings 4 100
Cisco Supervisor upgrade to 2T 3 71
ASA - RV130 VPN tunnel, cannot pass traffic 8 80
Fortigate Question 5 23
Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question