<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0 in Scripts</title>
    <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261636#M1237</link>
    <description>&lt;P&gt;Awesome Danny!&amp;nbsp; I ran it on VSX R82, but there where a bunch of interfaces it could not see as I suspect the script may not go into each vs and run per VS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Nov 2025 15:34:17 GMT</pubDate>
    <dc:creator>genisis__</dc:creator>
    <dc:date>2025-11-02T15:34:17Z</dc:date>
    <item>
      <title>Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261554#M1233</link>
      <description>169</description>
      <pubDate>Tue, 24 Mar 2026 13:38:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261554#M1233</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2026-03-24T13:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261576#M1234</link>
      <description>&lt;P&gt;Wow Danny, thats AMAZING!&lt;/P&gt;
&lt;P&gt;Just ran it in my lab.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-GW:0]# /var/log/cis/CIS_Benchmark_Gaia_v1.1.0.sh&lt;/P&gt;
&lt;P&gt;|-------------------------------------------------------------------------------+&lt;BR /&gt;| CIS Benchmark Checks for Check Point Gaia v1.1.0&lt;BR /&gt;|-------------------------------------------------------------------------------+&lt;BR /&gt;| 1. Password Policy | Score | Status | Value&lt;BR /&gt;| 1.1 Password Length 14+ | No | Default | 6&lt;BR /&gt;| 1.2 Disallow Palindromes | Yes | Customized | t&lt;BR /&gt;| 1.3 Password Complexity 3+ | No | Default | 2&lt;BR /&gt;| 1.4 Password History 12+ | No | Default | 10&lt;BR /&gt;| 1.5 Password Expiry max. 90 days | No | Default | never&lt;BR /&gt;| 1.6 Password Expiry Warning set to 7 | Yes | Customized | 7&lt;BR /&gt;| 1.7 Password Expiry Logout set to 1 | No | Default | never&lt;BR /&gt;| 1.8 Deny Acces to Used Accounts on | No | Default | off&lt;BR /&gt;| 1.9 Non-use days before lockout set to 30 | No | Default | 365&lt;BR /&gt;| 1.10 Force to change initial Password | No | Default | no&lt;BR /&gt;| 1.11 Deny Access after failed logins on | No | Default | off&lt;BR /&gt;| 1.12 Max. Fail-Attempts is set to 5 or lower | No | Default | 10&lt;BR /&gt;| 1.13 Down Time set to 300s or more | Yes | Customized | 1200&lt;BR /&gt;|-------------------------------------------------------------------------------+&lt;BR /&gt;| 2. Device Setup | Score | Status | Value&lt;BR /&gt;| 2.1 General Settings | | |&lt;BR /&gt;| 2.1.1 Login Banner is set | No | Default | Manually check banner message!&lt;BR /&gt;| 2.1.2 Message Of The Day (MOTD) is set | No | Disabled |&lt;BR /&gt;| 2.1.3 Core Dump enabled | No | Disabled | | 2.1.4 Config-state is saved | Yes | Default | Saved&lt;BR /&gt;| 2.1.5 Unused interfaces are disabled | Yes | - |&lt;BR /&gt;| 2.1.6 DNS server is configured | Yes | Customized | [8.8.8.8, 8.8.4.4, 1.1.1.1]&lt;BR /&gt;| 2.1.7 IPv6 is disabled (if not in use) | No | Customized |&lt;BR /&gt;| 2.1.8 Host Name is set | Yes | Customized | CP-GW&lt;BR /&gt;| 2.1.9 Telnet is disabled | Yes | Default | off&lt;BR /&gt;| 2.1.10 DHCP is disabled | Yes | Default | Disabled&lt;BR /&gt;|----------------------------------------------------------------------------------+&lt;BR /&gt;| 2.2 SNMP | Score | Status | Value&lt;BR /&gt;| 2.2.1 SNMP Agent is disabled | No | Default | Disabled&lt;BR /&gt;| 2.2.2 SNMP Agent version is set to v3-Only | Yes | Customized | v3-Only&lt;BR /&gt;| 2.2.3 SNMP traps enabled | No | Default |&lt;BR /&gt;| 2.2.4 SNMP traps receivers is set | No | Default |&lt;BR /&gt;|----------------------------------------------------------------------------------+&lt;BR /&gt;| 2.3 NTP | Score | Status | Value&lt;BR /&gt;| 2.3.1.(1) NTP is enabled | No | Default | Disabled&lt;BR /&gt;| 2.3.1.(2) NTP Servers (1&amp;amp;2) IPs are configured | Yes | Customized | 2&lt;BR /&gt;| 2.3.2 Timezone is set correctly | Yes | Customized | Canada/Eastern&lt;BR /&gt;|----------------------------------------------------------------------------------+&lt;BR /&gt;| 2.4 Backup | Score | Status | Value&lt;BR /&gt;| 2.4.1 System Backup is set | No | Default | Not set&lt;BR /&gt;| 2.4.2 Snapshot is set | No | Default | Not set&lt;BR /&gt;| 2.4.3 Scheduled Backups | No | - |&lt;BR /&gt;|----------------------------------------------------------------------------------+&lt;BR /&gt;| 2.5 Authentication Settings | Score | Status | Value&lt;BR /&gt;| 2.5.1 CLI Timeout is 10min or less | No | Default | 720 min&lt;BR /&gt;| 2.5.2 Web Session Timeout is 10min or less | No | Default | 720 min&lt;BR /&gt;| 2.5.3 (1) Telnet Authentication is disabled | Yes | Default | Disabled&lt;BR /&gt;| 2.5.3 (2) Client Authentication is SSL secured | No | Default | Insecure HTTP client auth&lt;BR /&gt;| 2.5.4 Radius or TACAS+ Server is configured | No | Default | Add Radius or TACACS+ server!&lt;BR /&gt;| 2.5.5 Only Allowed Clients for device mgmt | No | Default | Any&lt;BR /&gt;|----------------------------------------------------------------------------------+&lt;BR /&gt;| 2.6 Logging | Score | Status | Value&lt;BR /&gt;| 2.6.1 Mgmtauditlogs is set to on | Yes | Customized | t&lt;BR /&gt;| 2.6.2 Auditlog is set to permanent | Yes | Customized | permanent&lt;BR /&gt;| 2.6.3 Cplogs is set to on | No | Default | off&lt;BR /&gt;|----------------------------------------------------------------------------------+&lt;BR /&gt;| Summary: 14 out of 42 checks passed&lt;BR /&gt;| CIS Benchmark Score: 33%&lt;BR /&gt;+----------------------------------------------------------------------------------+&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 11:46:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261576#M1234</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-31T11:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261616#M1235</link>
      <description>&lt;P&gt;Also sent this to few customers Danny, they all LOVED it!&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 23:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261616#M1235</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-31T23:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261636#M1237</link>
      <description>&lt;P&gt;Awesome Danny!&amp;nbsp; I ran it on VSX R82, but there where a bunch of interfaces it could not see as I suspect the script may not go into each vs and run per VS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 15:34:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261636#M1237</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-11-02T15:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261638#M1239</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5933"&gt;@genisis__&lt;/a&gt;&amp;nbsp;: Thanks for testing on VSX. As I kept the script code highly readable and adjustable, it should be easy for you to add VSX support and share your result with us. What do you think?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 16:03:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261638#M1239</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-11-02T16:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261670#M1243</link>
      <description>&lt;P&gt;I've never actually tried it Danny.. not really a coder, but I can try to take a look.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 10:08:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261670#M1243</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-11-03T10:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261735#M1244</link>
      <description>&lt;P&gt;Great Script! Thanks!&lt;/P&gt;
&lt;P&gt;Is there a bug in 2.3.1 with NTP? I have in /config/active several lines for each NTP Server&lt;/P&gt;
&lt;LI-CODE lang="javascript"&gt;# grep -w "^ntp:server:.*\(t\)$"  /config/active
ntp:server:192.0.2.2 t
ntp:server:192.0.2.2:iburst t
ntp:server:192.0.2.1 t
ntp:server:192.0.2.1:iburst t
ntp:server:192.0.2.1:prefer t
&lt;/LI-CODE&gt;
&lt;P&gt;This counts the line to 5 and fails.&lt;/P&gt;
&lt;P&gt;Version R81.20 take118&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 06:50:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261735#M1244</guid>
      <dc:creator>Daniel_</dc:creator>
      <dc:date>2025-11-04T06:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261736#M1245</link>
      <description>&lt;P&gt;2.5.4 fails if only radius is configured. The script checks for "aaa:auth_order" but it's "aaa:auth_profile"&lt;/P&gt;
&lt;LI-CODE lang="javascript"&gt;# grep aaa:auth_profile /config/active
aaa:auth_profile:base_radius_authprofile:radius_srv:1 t
aaa:auth_profile:base_radius_authprofile:radius_srv:1:host 192.0.2.1
aaa:auth_profile:base_radius_authprofile:radius_srv:1:port 1812
aaa:auth_profile:base_radius_authprofile:radius_srv:1:secret topsecret
aaa:auth_profile:base_radius_authprofile:radius_srv:1:timeout 3
aaa:auth_profile:base_radius_authprofile:radius_srv:2 t
aaa:auth_profile:base_radius_authprofile:radius_srv:2:host 192.0.2.2
aaa:auth_profile:base_radius_authprofile:radius_srv:2:port 1812
aaa:auth_profile:base_radius_authprofile:radius_srv:2:secret topsecret
aaa:auth_profile:base_radius_authprofile:radius_srv:2:timeout 3&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 04 Nov 2025 08:00:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261736#M1245</guid>
      <dc:creator>Daniel_</dc:creator>
      <dc:date>2025-11-04T08:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261738#M1246</link>
      <description>&lt;P&gt;Thanks for testing. Please suggest a code fix.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 08:14:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261738#M1246</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-11-04T08:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261747#M1247</link>
      <description>&lt;P&gt;There are a few things that need to be fxed in the CIS benchmark.&lt;/P&gt;
&lt;P&gt;I have proposed 1 change allready. But there are some more notes that I have to work on. As a few more thins are not correct in my view.&lt;/P&gt;
&lt;P&gt;For example CIS benchmark 2.5.3. makes no sense on machines that are not a gateway.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 10:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261747#M1247</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2025-11-04T10:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Script to run the CIS Check Point Firewall Benchmark v1.1.0</title>
      <link>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261750#M1248</link>
      <description>&lt;P&gt;Yeah, I've seen your proposal &lt;A href="https://community.checkpoint.com/t5/General-Topics/Updating-CIS-Benchmarks/m-p/256661#M43247" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 06:25:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Script-to-run-the-CIS-Check-Point-Firewall-Benchmark-v1-1-0/m-p/261750#M1248</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-11-07T06:25:54Z</dc:date>
    </item>
  </channel>
</rss>

