<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auditing changes in FW in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258057#M50606</link>
    <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Smart console changes would be via audit logs, but something like what you described probably either smart event, or /var/log/audit dir.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 23 Sep 2025 22:56:26 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-09-23T22:56:26Z</dc:date>
    <item>
      <title>Auditing changes in FW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258056#M50605</link>
      <description>&lt;P&gt;Hello, Mates&lt;/P&gt;
&lt;P&gt;Is it possible to “observe” all the changes made by an administrator from the CLI of a FW?&lt;/P&gt;
&lt;P&gt;For example, if an administrator changes a route, edits an interface, adds a new interface, configures SNMPv2, configures OSPF... all this from the CLI of a FW...&lt;/P&gt;
&lt;P&gt;Is it possible to review this activity performed by an administrator in the logs? Or is it stored somewhere else on the device?&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 22:54:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258056#M50605</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-09-23T22:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing changes in FW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258057#M50606</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Smart console changes would be via audit logs, but something like what you described probably either smart event, or /var/log/audit dir.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 22:56:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258057#M50606</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-23T22:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing changes in FW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258058#M50607</link>
      <description>&lt;P&gt;On a second thought bro, I know our company uses syslog server for these things, when say someone logs into the firewall, we do get an alert about it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 23:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258058#M50607</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-23T23:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing changes in FW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258060#M50608</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1 (5).png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31518i496834261939C452/image-size/large?v=v2&amp;amp;px=999" role="button" title="1 (5).png" alt="1 (5).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Otherwise you would check&amp;nbsp;&lt;SPAN&gt;/var/log/messages&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 23:16:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258060#M50608</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-09-23T23:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing changes in FW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258063#M50610</link>
      <description>&lt;P&gt;Hi, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Does this configuration shown in your image also apply when changes are made via CLI on a firewall?&lt;/P&gt;
&lt;P&gt;If a change is successful, for example when you “delete” several VLANs, should we be able to see these changes in the SmartConsole Audit Logs?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 23:38:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258063#M50610</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-09-23T23:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing changes in FW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258064#M50611</link>
      <description>&lt;P&gt;Hey brother...keep in mind, those changes will NOT show up in smart console audit logs, because thats ONLY for changes made in smart console by default. However, you can make it work the way&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;posted, you just need to add mgmt server in remote system logging tab. Im sure you know that by default, fw logs will be sent to the management, but not ones you are referring to, unless you set this up first.&lt;/P&gt;
&lt;P&gt;I had done that before in the lab and was fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 23:44:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258064#M50611</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-23T23:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing changes in FW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258071#M50612</link>
      <description>&lt;P&gt;The audit logs are explicitly for any changed made by CLI on the system. So yes. We recommend you send them to syslog and then configure central syslog server to store them all in one place, so save you having to trawl the messages files on the systems and hope the entries you want haven't rotated away.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 02:08:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258071#M50612</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-09-24T02:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing changes in FW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258075#M50613</link>
      <description>&lt;P&gt;You need to implement&amp;nbsp;sk99134 or you will not know what your privileged users are doing&lt;/P&gt;
&lt;P&gt;/Henrik&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 06:18:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-changes-in-FW/m-p/258075#M50613</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2025-09-24T06:18:55Z</dc:date>
    </item>
  </channel>
</rss>

