<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule Analyzer without logging rules in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74601#M81800</link>
    <description>&lt;P&gt;Note that as a best practice, &lt;EM&gt;&lt;STRONG&gt;most&lt;/STRONG&gt;&lt;/EM&gt; of your rules should be logged.&lt;BR /&gt;The fact most of your rules are not logged is problematic for many reasons, including this specific exercise.&lt;/P&gt;
&lt;P&gt;Regardless of whether you log a rule or not, every rule should log the number of hits against that rule.&lt;BR /&gt;It doesn't show by default in R80.x SmartConsole, but it's easy enough to see by right-clicking on the rule headers and ticking the box for hits:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-02-09 at 6.10.19 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4381i5FB0358EB42E67C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-02-09 at 6.10.19 PM.png" alt="Screen Shot 2020-02-09 at 6.10.19 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If a rule has a low number of hits against it, that's a target for a rule that could potentially be removed.&lt;BR /&gt;In pre R80 releases for Check Point gateways, it was considered best practice to move rules that were hit a lot to the top of the rulebase to improve gateway performance.&lt;BR /&gt;With column-based matching added from R80.10, this is less needed, though there are still a few corner cases where it might help.&lt;/P&gt;
&lt;P&gt;As far as potentially simplifying rulebase logic, that's something a tool or a human would have to address.&lt;BR /&gt;We also offer, via Check Point Professional Services, a service called &lt;A href="https://www.checkpoint.com/support-services/design-deploy-operate-optimize/smartoptimize/" target="_self"&gt;SmartOptimize&lt;/A&gt; that can assist with this task as well.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Feb 2020 02:19:21 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-02-10T02:19:21Z</dc:date>
    <item>
      <title>Rule Analyzer without logging rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74371#M81797</link>
      <description>&lt;P&gt;Hi Everyone.&lt;/P&gt;&lt;P&gt;Im looking for some specific applicattion that they works like a Rule Analyzer.&lt;/P&gt;&lt;P&gt;We have a 64000 Chassis and 1600 rules. All of them are not logging exept the "Clean UP" rule.&lt;/P&gt;&lt;P&gt;We found the following applications but we need to know which of those are the best with that scenary&lt;/P&gt;&lt;P&gt;1. Firemon&lt;/P&gt;&lt;P&gt;2. Tuffin&lt;/P&gt;&lt;P&gt;3. Algo Sec&lt;/P&gt;&lt;P&gt;4. Skybox&lt;/P&gt;&lt;P&gt;PD: Please remember that we are not loggin rules! So we need to find some application that works without that.&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 19:38:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74371#M81797</guid>
      <dc:creator>MRossi92</dc:creator>
      <dc:date>2020-02-06T19:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Analyzer without logging rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74419#M81798</link>
      <description>What specific insights add you looking for from such a tool?&lt;BR /&gt;Without logging your rules, about all you have to work with are hit counts…or possibly the logic of specific rules.</description>
      <pubDate>Fri, 07 Feb 2020 10:27:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74419#M81798</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-07T10:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Analyzer without logging rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74489#M81799</link>
      <description>&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;Can you explain me how can i work with the "Hitcounts"?&lt;/P&gt;&lt;P&gt;We need some application that he can clean and optimize the security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 18:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74489#M81799</guid>
      <dc:creator>MRossi92</dc:creator>
      <dc:date>2020-02-07T18:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Analyzer without logging rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74601#M81800</link>
      <description>&lt;P&gt;Note that as a best practice, &lt;EM&gt;&lt;STRONG&gt;most&lt;/STRONG&gt;&lt;/EM&gt; of your rules should be logged.&lt;BR /&gt;The fact most of your rules are not logged is problematic for many reasons, including this specific exercise.&lt;/P&gt;
&lt;P&gt;Regardless of whether you log a rule or not, every rule should log the number of hits against that rule.&lt;BR /&gt;It doesn't show by default in R80.x SmartConsole, but it's easy enough to see by right-clicking on the rule headers and ticking the box for hits:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-02-09 at 6.10.19 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4381i5FB0358EB42E67C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-02-09 at 6.10.19 PM.png" alt="Screen Shot 2020-02-09 at 6.10.19 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If a rule has a low number of hits against it, that's a target for a rule that could potentially be removed.&lt;BR /&gt;In pre R80 releases for Check Point gateways, it was considered best practice to move rules that were hit a lot to the top of the rulebase to improve gateway performance.&lt;BR /&gt;With column-based matching added from R80.10, this is less needed, though there are still a few corner cases where it might help.&lt;/P&gt;
&lt;P&gt;As far as potentially simplifying rulebase logic, that's something a tool or a human would have to address.&lt;BR /&gt;We also offer, via Check Point Professional Services, a service called &lt;A href="https://www.checkpoint.com/support-services/design-deploy-operate-optimize/smartoptimize/" target="_self"&gt;SmartOptimize&lt;/A&gt; that can assist with this task as well.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 02:19:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74601#M81800</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-10T02:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Analyzer without logging rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74679#M81801</link>
      <description>&lt;P&gt;I thought you were referring to another tool with the "hitcounts".&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the answer and from your time but its not a good solution for a Firewall with 1700 rules. We need something more easy to the day work.&lt;/P&gt;&lt;P&gt;Someone know something from those applications?&lt;/P&gt;&lt;P&gt;1. Firemon&lt;/P&gt;&lt;P&gt;2. Tuffin&lt;/P&gt;&lt;P&gt;3. Algo Sec&lt;/P&gt;&lt;P&gt;4. Skybox&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 13:25:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74679#M81801</guid>
      <dc:creator>MRossi92</dc:creator>
      <dc:date>2020-02-10T13:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Analyzer without logging rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74722#M81802</link>
      <description>&lt;P&gt;You could use netflow with some netflow analyzer, but it costs performance on the gateways. Better be careful when using it on heavy load gateways.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 18:53:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74722#M81802</guid>
      <dc:creator>Daniel_Schlifka</dc:creator>
      <dc:date>2020-02-10T18:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Analyzer without logging rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74751#M81803</link>
      <description>You still haven’t answered the question of what you hope to achieve by using one of these tools.&lt;BR /&gt;In any case, those tools are only as effective as the data they are fed.&lt;BR /&gt;Not having logs for the most part is a huge blind spot.</description>
      <pubDate>Tue, 11 Feb 2020 04:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74751#M81803</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-11T04:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Analyzer without logging rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74752#M81804</link>
      <description>Netflow will only tell you about active connections.&lt;BR /&gt;It won’t tell you anything about historical connections.&lt;BR /&gt;Perhaps over time the historical data can assist, but that still seems like a manual process.</description>
      <pubDate>Tue, 11 Feb 2020 04:17:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rule-Analyzer-without-logging-rules/m-p/74752#M81804</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-11T04:17:14Z</dc:date>
    </item>
  </channel>
</rss>

