<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint Umbrella Integration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149837#M24062</link>
    <description>&lt;P&gt;No - are you aware of any CheckPoint Log File for the Tracking with "UserAlert1"?&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 15:11:19 GMT</pubDate>
    <dc:creator>D_W</dc:creator>
    <dc:date>2022-05-31T15:11:19Z</dc:date>
    <item>
      <title>CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149832#M24058</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;anyone here that uses the Cisco Umbrella CheckPoint Integration?&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.umbrella.com/hc/en-us/articles/231248788" target="_blank"&gt;https://support.umbrella.com/hc/en-us/articles/231248788&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're here on GW R80.40 and Management R81.10. Script is located in $FWDIR/bin on the Gateway. UserAlert1 is defined in GlobalProperties and a ThreatPrevention Rule is set to execute UserAlert1 when matched. But issue is that the script never gets triggered.&lt;/P&gt;&lt;P&gt;Manually execution of the script show's that it is communication with the Umbrella destination.&lt;BR /&gt;Every hint is very much appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; !&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 14:16:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149832#M24058</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2022-05-31T14:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149833#M24059</link>
      <description>&lt;P&gt;Just a shot in the dark here, but do you see any relevant logs in dashboard? Anything related to script not being executed? If there is specific IP related to Cisco side, you can always try run fw ctl zdebug + drop | grep x.x.x.x on CP fw (just replace with relevant IP address)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 14:38:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149833#M24059</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-05-31T14:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149835#M24060</link>
      <description>&lt;P&gt;I see a log to &lt;SPAN&gt;67.215.70.75&lt;/SPAN&gt; (&lt;SPAN&gt;s-platform.api.opendns.com&lt;/SPAN&gt;) when I manually execute the script.&lt;/P&gt;&lt;P&gt;I see the Threat Prevention rule matches and a log is generated with Type "Alert" but not log that shows outgoing traffic to &lt;SPAN&gt;67.215.70.75&lt;/SPAN&gt;.&lt;BR /&gt;Also I added some code that writes into a file when the script is running for logging if the script was executed or not but nothing...&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 14:47:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149835#M24060</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2022-05-31T14:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149836#M24061</link>
      <description>&lt;P&gt;any errors?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 15:09:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149836#M24061</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-05-31T15:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149837#M24062</link>
      <description>&lt;P&gt;No - are you aware of any CheckPoint Log File for the Tracking with "UserAlert1"?&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 15:11:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149837#M24062</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2022-05-31T15:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149841#M24063</link>
      <description>&lt;P&gt;Have not seen it in a while.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 16:00:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149841#M24063</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-05-31T16:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149847#M24066</link>
      <description>&lt;P&gt;Do the scripts exist on the gateways and can you confirm they execute correctly?&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 16:17:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149847#M24066</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-05-31T16:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149909#M24086</link>
      <description>&lt;P&gt;Yes I can confirm that the script is on the GW and executes correctly when started manually... see below the details of the script and what comes back when I send bogus information executed manually.&lt;BR /&gt;In the curl_cli I had to add "-k" because the Let'SEncrypt Cert cannot be validated by the GW &lt;span class="lia-unicode-emoji" title=":expressionless_face:"&gt;😑&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-06-01_08-30.png" style="width: 936px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16781i7D4C4F523D0C3ECA/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-06-01_08-30.png" alt="2022-06-01_08-30.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 07:09:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/149909#M24086</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2022-06-01T07:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/198367#M37129</link>
      <description>&lt;P&gt;Do you solve the problem?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 09:31:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/198367#M37129</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2023-11-20T09:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Umbrella Integration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/198649#M37202</link>
      <description>&lt;P&gt;I'm also interested in the solution.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 13:46:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-Umbrella-Integration/m-p/198649#M37202</guid>
      <dc:creator>6a8496cf-c878-4</dc:creator>
      <dc:date>2023-11-22T13:46:27Z</dc:date>
    </item>
  </channel>
</rss>

