<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LEA port not listening in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23653#M98513</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My question is: why do you need to use multiple LEA ports?&lt;/P&gt;&lt;P&gt;Particularly when they are both unauthenticated?&lt;/P&gt;&lt;P&gt;The only place I've seen two different LEA ports used is when one of them is authenticated, the other is not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something like in this SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk89620" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk89620"&gt;Configuring a Log Server R76 and lower to work with both SmartEvent component and an OPSEC LEA server&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't believe you can do two unauthenticated LEA ports.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2030"&gt;https://community.checkpoint.com/people/bbent09791668-5ef8-377b-845e-545aff695211&lt;/A&gt;‌?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Jan 2018 05:28:26 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-01-17T05:28:26Z</dc:date>
    <item>
      <title>LEA port not listening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23652#M98512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a Checkpoint Log Server that is the center point of logs for 6 firewalls. I've setup a LEA connection to that server from a SOC log collection appliance, TCP 18186, which works fine, and another one to a QRadar SIEM 18185 which doesn't work at all. I've restarted services and rebooted, the LogServer just wont listen on the port. I've confirmed this with netstat. Attached is the fwopsec file from the Checkpoint logs server. Any help is appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 00:15:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23652#M98512</guid>
      <dc:creator>Justin_Hickey</dc:creator>
      <dc:date>2018-01-17T00:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: LEA port not listening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23653#M98513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My question is: why do you need to use multiple LEA ports?&lt;/P&gt;&lt;P&gt;Particularly when they are both unauthenticated?&lt;/P&gt;&lt;P&gt;The only place I've seen two different LEA ports used is when one of them is authenticated, the other is not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something like in this SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk89620" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk89620"&gt;Configuring a Log Server R76 and lower to work with both SmartEvent component and an OPSEC LEA server&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't believe you can do two unauthenticated LEA ports.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2030"&gt;https://community.checkpoint.com/people/bbent09791668-5ef8-377b-845e-545aff695211&lt;/A&gt;‌?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 05:28:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23653#M98513</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-17T05:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: LEA port not listening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23654#M98514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Dameon. I didn't realize that I could point two log sources at the same LEA instance. When you say "unauthenticated", I mean, they do exchange certificates and SIC information. Would you say they are still unauthenticated in that instance ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 12:36:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23654#M98514</guid>
      <dc:creator>Justin_Hickey</dc:creator>
      <dc:date>2018-01-17T12:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: LEA port not listening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23655#M98515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;We had a similar issue long back for R80 management. At that time the issue was fixed after restatting the QRadar services only after make sure of the authentication type and port on both QRadar and log server are same.&amp;nbsp;&lt;/SPAN&gt;&lt;P class=""&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 16:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23655#M98515</guid>
      <dc:creator>Ni_c</dc:creator>
      <dc:date>2018-01-17T16:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: LEA port not listening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23656#M98516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I mean unauthenticated.&lt;/P&gt;&lt;P&gt;This is based on what it says in&amp;nbsp;sk89620 and the screenshot of your fwopsec.conf says.&lt;/P&gt;&lt;P&gt;You probably want to change the line to auth_port instead of just port if you want SIC authentication &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that LEA has been multi-threaded (and able to support multiple endpoints connecting) since R77.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 16:52:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23656#M98516</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-17T16:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: LEA port not listening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23657#M98517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What Dameon said &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Would just add that if both do SIC, then there's no need for the fwopsec.conf edits. Use the defaults and have them connect on the same port 18184. Will simplify things when you do an upgrade.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 17:15:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23657#M98517</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2018-01-17T17:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: LEA port not listening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23658#M98518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the many responses. Couldn't get it to work on 18184. I did a tcpdump and currently traffic between log and management server exist on that port. I got it work with 18186 but most of the pertinent fields come across as *** Confidential *** . I'm assuming perhaps checkpoint doesn't like to send this info across the wire in the clear ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Going to try 18184 again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 19:46:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23658#M98518</guid>
      <dc:creator>Justin_Hickey</dc:creator>
      <dc:date>2018-01-17T19:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: LEA port not listening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23659#M98519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Second try worked with 18184, going to change my other log source as well. Thanks for all the help. I haven't worked on Checkpoints for 10+ years back when they were on Nokias so I am more than a little rusty. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This guide was helpful on the QRADAR side.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/t_DSM_guide_Checkpoint_firewall1_OPSECLEA.html#t_dsm_guide_checkpoint_firewall1_opseclea"&gt;https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/t_DSM_guide_Checkpoint_firewall1_OPSECLEA.html#t_dsm_guide_checkpoint_firewall1_opseclea&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 20:10:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23659#M98519</guid>
      <dc:creator>Justin_Hickey</dc:creator>
      <dc:date>2018-01-17T20:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: LEA port not listening</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23660#M98520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great to hear &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;I still have a few Nokia boxes at my house from back in the days when I worked there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 20:25:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-port-not-listening/m-p/23660#M98520</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-17T20:25:16Z</dc:date>
    </item>
  </channel>
</rss>

