<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108800#M14735</link>
    <description>&lt;P&gt;What I'm being asked today on this....&amp;nbsp; I said I would request an enhancement.&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":kissing_face_with_closed_eyes:"&gt;😚&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Per auditor request, this requirement asks for system-generated lists of production configuration changes for the past 12 months. Will generating a list of 100 always cover an entire year for future audits? Is it not possible to change the setting to a period of time (1 year) instead of a number (100)?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2021 20:33:47 GMT</pubDate>
    <dc:creator>Daniel_Kavan</dc:creator>
    <dc:date>2021-01-25T20:33:47Z</dc:date>
    <item>
      <title>FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108521#M14639</link>
      <description>&lt;P&gt;Is there a command to issue to show when I manually updated gateway's JHF/versions with CPUSE?&amp;nbsp; RE: 80.10, 80.20, 80.30, R80.40, R81.&amp;nbsp; Specifically they want S&lt;SPAN&gt;ystem generated list of production configuration changes for the past 12 months (including software and firmware updates/patches, firewall/router/switch configuration changes, etc.) in excel format&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Currently, I am NOT using the CDT.&lt;/P&gt;&lt;P&gt;Some of my gateway's have recently been formatted and rebuilt, so not much history there.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 14:25:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108521#M14639</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2021-01-22T14:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108535#M14644</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/599"&gt;@Daniel_Kavan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Several options here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- you can use the 'cpinfo -y all' command to see list of installed hotfixes&lt;/P&gt;
&lt;P&gt;- in clish you can run 'show installer installed packages' or 'show installer download packages' and so on...&lt;/P&gt;
&lt;P&gt;- you can check /opt/CPInstLog/DA_Actions.xml for installed JHF/versions/etc...&lt;/P&gt;
&lt;P&gt;- If you are using R81 and you installed your hotfixes/JHF via SmartConsole you can see the list there&lt;/P&gt;
&lt;P&gt;- for configuration/routing/etc... you have the 'show config' clish command&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-and of course in CPUSE webUI you can see the list of hotfixes that are installed&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 15:23:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108535#M14644</guid>
      <dc:creator>shlomip</dc:creator>
      <dc:date>2021-01-22T15:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108536#M14645</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;RE: software updates: Thank you.&amp;nbsp; That&amp;nbsp;DA_Actions.xml&amp;nbsp; file is perfect.&lt;/P&gt;&lt;P&gt;RE: configuration The auditors aren't looking for the current configuration(show configuration), they want the history of changes over and throughout 2020.&amp;nbsp; &amp;nbsp;I turned in a 'diff' on a configuration early and later in the year.&amp;nbsp; We'll see how they like that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 18:08:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108536#M14645</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2021-01-22T18:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108557#M14648</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8469"&gt;@Tsahi_Etziony&lt;/a&gt;&amp;nbsp;does CPUSE track history in this way?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 17:35:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108557#M14648</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-22T17:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108712#M14710</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;CPUSE track installation history in DA_Actions.xml (100 last actions including internally initiated actions like Deployment Agent self update).&lt;/P&gt;
&lt;P&gt;It does not track configuration changes that are seen on "show configuration"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 06:11:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108712#M14710</guid>
      <dc:creator>Boaz_Orshav</dc:creator>
      <dc:date>2021-01-25T06:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108800#M14735</link>
      <description>&lt;P&gt;What I'm being asked today on this....&amp;nbsp; I said I would request an enhancement.&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":kissing_face_with_closed_eyes:"&gt;😚&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Per auditor request, this requirement asks for system-generated lists of production configuration changes for the past 12 months. Will generating a list of 100 always cover an entire year for future audits? Is it not possible to change the setting to a period of time (1 year) instead of a number (100)?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 20:33:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108800#M14735</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2021-01-25T20:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108804#M14737</link>
      <description>&lt;P&gt;If you're making a LOT of changes in a year, or we update the Deployment Agent a lot of times, or a combination thereof, then maybe not.&lt;BR /&gt;Unless&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19244"&gt;@Boaz_Orshav&lt;/a&gt;&amp;nbsp;or someone else says this is tunable somehow, I'd make a formal request through your local Check Point office.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 22:40:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108804#M14737</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-25T22:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108830#M14750</link>
      <description>&lt;P&gt;Every modification on the gateway should be properly documented internally. Most orgs are using ticketing tools for that, where you are allowed to do something only in case you have valid ticket for it.&lt;/P&gt;
&lt;P&gt;That said, if you have it in place, it is matter of couple of clicks in the ticketing tool to get all tickets within specific timestamp which were done on the gateway.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 07:05:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108830#M14750</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2021-01-26T07:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: FISMA auditor wants to see a command generated history of configuration/JHF changes done on a gw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108831#M14751</link>
      <description>&lt;P&gt;Notice these are two different things:&lt;/P&gt;
&lt;P&gt;1. Show configuration - related to OS configuration. CPUSE is not aware of (most) of these changes hence can't track them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Packages deployed by CPUSE (HF/Jumbo/Version upgrade) - this can be a nice enhancement to keep track of. As suggested above - I also think the best way to make it happen is to formalize the request.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 07:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FISMA-auditor-wants-to-see-a-command-generated-history-of/m-p/108831#M14751</guid>
      <dc:creator>Boaz_Orshav</dc:creator>
      <dc:date>2021-01-26T07:08:07Z</dc:date>
    </item>
  </channel>
</rss>

