<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Administrator daily routines in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205999#M38902</link>
    <description>&lt;P&gt;I wrote the first one that just checked the backups via "show backups status" using HeikoAnkenbrand's earlier version of gw_multi_commands&lt;BR /&gt;REF: &lt;A href="https://community.checkpoint.com/t5/Scripts/GAIA-Easy-execute-CLI-commands-on-all-gateways-simultaneously/td-p/50883" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/GAIA-Easy-execute-CLI-commands-on-all-gateways-simultaneously/td-p/50883&lt;/A&gt;&lt;BR /&gt;It was ok for a quick look at backups every morning.&lt;/P&gt;&lt;P&gt;I wont share the new script as it will become added value for our clients.&lt;BR /&gt;But for an overview it is BASH with if/then and awk&lt;BR /&gt;* mgmt_cli to extract the domains from the MDM and then their gateways&lt;BR /&gt;* $CPDIR/bin/cprid_util to run remote commands on the GW's which is using SIC to connect&lt;BR /&gt;* Output file is populated with all the data and formats it to HTML&lt;BR /&gt;* More if/thens to create emails to the services desk&lt;BR /&gt;* Uses an internal smtp relay to forward the email&lt;/P&gt;</description>
    <pubDate>Tue, 13 Feb 2024 20:14:26 GMT</pubDate>
    <dc:creator>spottex</dc:creator>
    <dc:date>2024-02-13T20:14:26Z</dc:date>
    <item>
      <title>Administrator daily routines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/204980#M38645</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In this post, I'm embarking on a journey to uncover the daily habits of firewall administrators! My goal is to not only equip myself but also empower others reading this to become more confident and effective guardians of our networks.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1-What daily security checks should I perform as a Checkpoint firewall admin to identify potential attacks?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2-Seeking insights:&lt;/STRONG&gt; What elements and daily checks should be included in an expert's Checkpoint firewall security report?&lt;/P&gt;&lt;P&gt;3-What is the most important thing that you need to check very often to make sure that your network is safe?&lt;/P&gt;&lt;P&gt;4-In your experience, what continuous monitoring practice provides the most actionable intelligence for securing a network?&lt;/P&gt;&lt;P&gt;5-What are your &lt;STRONG&gt;daily routines&lt;/STRONG&gt; as a firewall administrator?&lt;/P&gt;&lt;P&gt;6-I'm curious about the daily practices of a firewall administrator. What specific checks and configurations do you prioritize?&lt;/P&gt;&lt;P&gt;Any more ideas are welcome!&amp;nbsp;Don't hesitate to share any additional thoughts or suggestions you have!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Moudar&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 11:16:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/204980#M38645</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-02-04T11:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator daily routines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/204983#M38647</link>
      <description>&lt;P&gt;I will see if I can find a good doc customer sent me while back about this, so glad you made this post, absolutely relevant.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 15:34:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/204983#M38647</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-04T15:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator daily routines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/204984#M38648</link>
      <description>&lt;P&gt;And while I look for the doc, below are some great references.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.process.st/templates/network-administrator-daily-tasks/" target="_blank"&gt;https://www.process.st/templates/network-administrator-daily-tasks/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Check-Point-Firewall-Admin-Tasks/td-p/37185" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Check-Point-Firewall-Admin-Tasks/td-p/37185&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cgtechnologies.com/security/firewall-audit-checklist/" target="_blank"&gt;https://www.cgtechnologies.com/security/firewall-audit-checklist/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/palo-alto-daily-admin-tasks/td-p/72108" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/palo-alto-daily-admin-tasks/td-p/72108&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.infrassist.com/firewall-audit-checklist/" target="_blank"&gt;https://www.infrassist.com/firewall-audit-checklist/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 15:37:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/204984#M38648</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-04T15:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator daily routines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205038#M38657</link>
      <description>&lt;P&gt;Excited to dive into the linked resources, but wouldn't it be amazing to combine that with your personal wisdom? If you're willing to share some of your daily habits and how they've shaped your work, I'd be incredibly grateful!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 10:46:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205038#M38657</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-02-05T10:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator daily routines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205039#M38658</link>
      <description>&lt;P&gt;I would be happy to share if I were fw admin myself, which Im not lol&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 10:48:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205039#M38658</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-05T10:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator daily routines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205799#M38840</link>
      <description>&lt;P&gt;We have a new engineer in our team who has updated a nightly script running on a MDM which checks all the GW's to see if backups have run. It now also looks for core dumps, snapshots the hosts resources and uptime, gets installed hotfixes which reports in a html table via email every morning.&amp;nbsp;&lt;BR /&gt;He has added secondary emails to the Service Desk to log a support ticket to the Security Team for each backup that fails and if any core dumps are found.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 19:26:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205799#M38840</guid>
      <dc:creator>spottex</dc:creator>
      <dc:date>2024-02-12T19:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator daily routines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205849#M38859</link>
      <description>&lt;P&gt;The automation of processes is a hot topic these days, and I'm definitely intrigued! Could you delve deeper into it, particularly exploring the different tools we could leverage? Specifically, I'm curious about using Ansible scripts, Python scripts, or even leveraging Management APIs. The ideas of what to automate are most important,&amp;nbsp;&lt;SPAN&gt;hence, additional insights into potential automation targets would be immensely valuable.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 08:18:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205849#M38859</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-02-13T08:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator daily routines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205999#M38902</link>
      <description>&lt;P&gt;I wrote the first one that just checked the backups via "show backups status" using HeikoAnkenbrand's earlier version of gw_multi_commands&lt;BR /&gt;REF: &lt;A href="https://community.checkpoint.com/t5/Scripts/GAIA-Easy-execute-CLI-commands-on-all-gateways-simultaneously/td-p/50883" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/GAIA-Easy-execute-CLI-commands-on-all-gateways-simultaneously/td-p/50883&lt;/A&gt;&lt;BR /&gt;It was ok for a quick look at backups every morning.&lt;/P&gt;&lt;P&gt;I wont share the new script as it will become added value for our clients.&lt;BR /&gt;But for an overview it is BASH with if/then and awk&lt;BR /&gt;* mgmt_cli to extract the domains from the MDM and then their gateways&lt;BR /&gt;* $CPDIR/bin/cprid_util to run remote commands on the GW's which is using SIC to connect&lt;BR /&gt;* Output file is populated with all the data and formats it to HTML&lt;BR /&gt;* More if/thens to create emails to the services desk&lt;BR /&gt;* Uses an internal smtp relay to forward the email&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 20:14:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Administrator-daily-routines/m-p/205999#M38902</guid>
      <dc:creator>spottex</dc:creator>
      <dc:date>2024-02-13T20:14:26Z</dc:date>
    </item>
  </channel>
</rss>

