<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: STIG's Forum in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/STIG-s-Forum/m-p/228760#M44048</link>
    <description>&lt;P&gt;Thank you PhoneBoy!!!&lt;/P&gt;&lt;P&gt;Any chance the "Fail-Closed" is documented in a released publicly available document. I will need to point to the document that shows this for my STIG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...and thank you the link to this forum. I will be looking checking it out all day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Oct 2024 14:48:05 GMT</pubDate>
    <dc:creator>Mike314</dc:creator>
    <dc:date>2024-10-02T14:48:05Z</dc:date>
    <item>
      <title>STIG's Forum</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/STIG-s-Forum/m-p/228693#M44033</link>
      <description>&lt;P&gt;Any chance we can get a forum to discuss STIG concerns?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From time-to-time we get a STIG that is not documented in the released documentation for given hardware/software.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The current example I am looking for is...&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;Check Text&lt;/STRONG&gt;&lt;SPAN&gt;: Verify the firewall stops forwarding traffic or maintains the configured security policies upon the failure of the following: system initialization, shutdown, or system abort.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If the firewall does not stop forwarding traffic or maintain the configured security policies upon the failure of system initialization, shutdown, or system abort, this is a finding.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;Fix Text&lt;/STRONG&gt;: Configure the firewall to stop forwarding traffic or maintain the configured security policies upon the failure of the following actions: system initialization, shutdown, or system abort."&lt;/DIV&gt;&lt;P&gt;------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;I have not been able to find any information about the traffic flow during a reboot, or system failure for the system I am using.&lt;/P&gt;&lt;P&gt;What is the best location to find answers on these types of topics? In the past, if I can not find documentation on a particular subject required for a STIG, I end up opening a ticket. It seems like that is a lot of overhead for something a lot of people need to do.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 21:29:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/STIG-s-Forum/m-p/228693#M44033</guid>
      <dc:creator>Mike314</dc:creator>
      <dc:date>2024-10-01T21:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: STIG's Forum</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/STIG-s-Forum/m-p/228697#M44034</link>
      <description>&lt;P&gt;You can ask here and we'll do our best to answer.&lt;/P&gt;
&lt;P&gt;By default, the system will not forward traffic when powered on and won't until the software is up where IP forwarding is enabled and the last installed security policy is activated.&lt;BR /&gt;The management is checked first to see if this policy has changed.&lt;BR /&gt;If the policy is the same or the management is not available for some reason, the gateway will attempt to load the last installed security policy from the local cache.&lt;BR /&gt;If all else fails, a DefaultFilter is loaded, which blocks all but management traffic and disables IP forwarding.&lt;/P&gt;
&lt;P&gt;Should the software in the gateway fail, it "fails closed" (won't forward any traffic).&lt;/P&gt;
&lt;P&gt;Some of this is in the formal documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Boot-Security.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Boot-Security.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 02:51:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/STIG-s-Forum/m-p/228697#M44034</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-02T02:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: STIG's Forum</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/STIG-s-Forum/m-p/228760#M44048</link>
      <description>&lt;P&gt;Thank you PhoneBoy!!!&lt;/P&gt;&lt;P&gt;Any chance the "Fail-Closed" is documented in a released publicly available document. I will need to point to the document that shows this for my STIG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...and thank you the link to this forum. I will be looking checking it out all day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 14:48:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/STIG-s-Forum/m-p/228760#M44048</guid>
      <dc:creator>Mike314</dc:creator>
      <dc:date>2024-10-02T14:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: STIG's Forum</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/STIG-s-Forum/m-p/228763#M44049</link>
      <description>&lt;P&gt;Not sure we directly address the "fail closed" issue.&lt;BR /&gt;However, if we failed open, we would not offer (as an option) fail open NICs, which are described here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk87621" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk87621&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 15:03:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/STIG-s-Forum/m-p/228763#M44049</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-02T15:03:34Z</dc:date>
    </item>
  </channel>
</rss>

