<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Architecture question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59662#M84693</link>
    <description>I asked the sales rep but they said we don't have multidomain licenses.</description>
    <pubDate>Mon, 05 Aug 2019 15:26:59 GMT</pubDate>
    <dc:creator>Agent_Smith</dc:creator>
    <dc:date>2019-08-05T15:26:59Z</dc:date>
    <item>
      <title>Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59286#M84683</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currently have two domains.&lt;/P&gt;&lt;P&gt;1 Domain for DEV which has a MGT station, Firewall Cluster, and Log Server.&lt;/P&gt;&lt;P&gt;1 Domain for Prod which has 2 MGT staitons ( 1 is in HA ) 3 Firewall Clusters each with their own Log Server.&lt;/P&gt;&lt;P&gt;I have 3 questions. Our sales rep told us multi-domain is overkill.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;We'd like to have central logging. Can we get rid of all Log Servers and send logs from DEV &amp;amp; Prod firewalls (separate domains) to a central Log Server and keep different MGT stations for DEV and Prod.&lt;/LI&gt;&lt;LI&gt;If we wanted add a third MGT station to the PRD domain can we?&lt;/LI&gt;&lt;LI&gt;Can we send logs from a firewall cluster to two separate Log Servers. One of which belongs to a different domain. Can we send logs from the DEV firewalls ( SIC with the DEV MGT station ) to the central Log Server that is going SIC with the Prod MGT station.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 21:33:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59286#M84683</guid>
      <dc:creator>Agent_Smith</dc:creator>
      <dc:date>2019-07-30T21:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59287#M84684</link>
      <description>Sounds like you should be using Multi-Domain.&lt;BR /&gt;Why do you not want to use it?</description>
      <pubDate>Tue, 30 Jul 2019 22:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59287#M84684</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-30T22:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59288#M84685</link>
      <description>Our Sales Rep said we should not be using it because we are too small of a deployment / organization.</description>
      <pubDate>Tue, 30 Jul 2019 22:46:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59288#M84685</guid>
      <dc:creator>Agent_Smith</dc:creator>
      <dc:date>2019-07-30T22:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59309#M84686</link>
      <description>&lt;P&gt;&amp;nbsp;Agent_Smith,&lt;/P&gt;&lt;P&gt;first of all I would like to send greetings from Neo...&lt;/P&gt;&lt;P&gt;Best solution for you will be using MultiDomain-Management. With this ou have separate management-domains, separate log servers, but you can see logs from both domains with one logviewer.&lt;/P&gt;&lt;P&gt;With your actual configuration you can't send logs from a gateway to a logserver in another management-domain. You need SIC beetween gateway and logserver and it's not possible to have more then one SIC-trust.&lt;/P&gt;&lt;P&gt;Another way to get the logs from both domains would be using a third party logserver. We had customer the are using SPLUNK. All gateways and management servers sends there logs via Log-Exporter&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_blank" rel="noopener"&gt;Log Exporter - Check Point Log Export&lt;/A&gt;&amp;nbsp;to the SPLUNK server. There is a nice CheckPoint app for splunk available, this gives you a similar view of the logs like in SmartConsole.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With Log-Exporter you can send your logs to any other Syslog-server not only splunk, maybee this is a solution for you.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 06:20:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59309#M84686</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-07-31T06:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59392#M84687</link>
      <description>&lt;P&gt;My understanding is that sending logs to Splunk or another syslog server limits the functionality of the logs because of the view. Can the Splunk App see traffic data?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was told by the sales rep that independent of the SIC you can send logs from a firewall to a different log server. That SIC is only established between MGT and Firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we have more than 2 MGT stations on one domain?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 20:42:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59392#M84687</guid>
      <dc:creator>Agent_Smith</dc:creator>
      <dc:date>2019-07-31T20:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59395#M84688</link>
      <description>&lt;P&gt;Agent_Smith,&lt;/P&gt;&lt;P&gt;what dou you mean with „traffic data“ to shown in splunk?&lt;/P&gt;&lt;P&gt;There was a threat here for the splunk app&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Logging-and-Reporting/New-Splunk-App-for-Check-Point-Logs/td-p/15873" target="_blank" rel="noopener"&gt;New-Splunk-App-for-Check-Point-Logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can send logs from a gateway to more then one logserver, but they all have to be in the same domain.&lt;/P&gt;&lt;P&gt;Yes, you can have two management server, but they are running in HA, meaning one is active an the another one is standby.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 21:08:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59395#M84688</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-07-31T21:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59396#M84689</link>
      <description>We have 2 MGT servers with 1 running in HA. Can we setup 2 more in HA?&lt;BR /&gt;&lt;BR /&gt;By traffic I mean can we see firewall drops and accepts of all traffic or is the App like some kind of SmartEvent watereddown.</description>
      <pubDate>Wed, 31 Jul 2019 21:11:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59396#M84689</guid>
      <dc:creator>Agent_Smith</dc:creator>
      <dc:date>2019-07-31T21:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59400#M84690</link>
      <description>&lt;P&gt;You can have only one management server and one HA management server per domain. But you can have more log servers.&lt;/P&gt;&lt;P&gt;In Check Points app for splunk you had a view like in smart event, but you can see the Check Point firewall raw logs in the normal splunk view.&lt;/P&gt;&lt;P&gt;Here is a copy of an example from&amp;nbsp;&lt;A href="https://weekly-geekly.github.io/articles/325170/index.html" target="_blank" rel="noopener"&gt;https://weekly-geekly.github.io/articles/325170/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="26126C0E-A663-4EB8-9B74-DB1CBB6ADE8B.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2041iE8D22727C0BCADDA/image-size/large?v=v2&amp;amp;px=999" role="button" title="26126C0E-A663-4EB8-9B74-DB1CBB6ADE8B.png" alt="26126C0E-A663-4EB8-9B74-DB1CBB6ADE8B.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 21:33:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59400#M84690</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-07-31T21:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59442#M84691</link>
      <description>I would imagine looking at drops and accepts in raw Splunk would be useless.&lt;BR /&gt;I have received misinfo from my sales rep.&lt;BR /&gt;I was told that you can send logs from firewalls to multiple destinations one of which doesn't have to be in your domain and I was told we can have more than 2 MGT stations per domain.</description>
      <pubDate>Thu, 01 Aug 2019 14:55:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59442#M84691</guid>
      <dc:creator>Agent_Smith</dc:creator>
      <dc:date>2019-08-01T14:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59589#M84692</link>
      <description>Did you get a cost breakdown between going MDM and not MDM?&lt;BR /&gt;My understanding is that MDM should be cheaper, unless you're reusing some older licenses or something.&lt;BR /&gt;&lt;BR /&gt;It seems feasible that you could send logs to an externally managed log server. &lt;BR /&gt;We definitely support, for instance, a locally managed SMB appliance sending logs to a log server.&lt;BR /&gt;I don't see a specific procedure for what you're describing.&lt;BR /&gt;&lt;BR /&gt;In any case, this would be a lot easier with Multi-Domain since all the SIC trust should "just work" due to a common ICA.</description>
      <pubDate>Sun, 04 Aug 2019 18:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59589#M84692</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-04T18:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59662#M84693</link>
      <description>I asked the sales rep but they said we don't have multidomain licenses.</description>
      <pubDate>Mon, 05 Aug 2019 15:26:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59662#M84693</guid>
      <dc:creator>Agent_Smith</dc:creator>
      <dc:date>2019-08-05T15:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Architecture question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59663#M84694</link>
      <description>Do you have the required licenses to do what you're proposing now or do you still need to buy licenses?</description>
      <pubDate>Mon, 05 Aug 2019 15:34:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Architecture-question/m-p/59663#M84694</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-05T15:34:48Z</dc:date>
    </item>
  </channel>
</rss>

