<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help in preparing benchmark documents for Checkpoint firewall in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/64864#M13255</link>
    <description>It’s not clear what you mean by “Risk Factors” here.&lt;BR /&gt;This also looks like a mix of Global Properties, OS settings, etc.&lt;BR /&gt;Can you provide some context around the question?</description>
    <pubDate>Sat, 12 Oct 2019 01:30:53 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-10-12T01:30:53Z</dc:date>
    <item>
      <title>Need help in preparing benchmark documents for Checkpoint firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/64701#M13250</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Can anyone help me and tell me the "RISK factors" for the following benchmark conditions:&lt;/P&gt;&lt;P&gt;Ensure Password Minimum length is set&lt;BR /&gt;Ensure Password Syntax: Character Types is set&lt;BR /&gt;Ensure Password Syntax: ID within Password is set&lt;BR /&gt;Ensure Maximun signon attempts is set&lt;BR /&gt;Ensure Lockout duration is set&lt;BR /&gt;Ensure Reset account lockout counter after&lt;BR /&gt;User login to system/device&lt;BR /&gt;User logoout from system/device&lt;BR /&gt;Retention of created log files&lt;BR /&gt;Connection matched by SAM&lt;BR /&gt;VPN packet handling errors&lt;BR /&gt;VPN configuration &amp;amp; key exchange errors&lt;BR /&gt;IP Options drop&lt;BR /&gt;File Transfer Protocol (FTP)&lt;BR /&gt;Unused Interfaces access&lt;BR /&gt;Dynamic routing protocols&lt;BR /&gt;ICMP virtual session timeout&lt;BR /&gt;Accept stateful UDP replied for unknown services&lt;BR /&gt;Accept Stateful ICMP replies&lt;BR /&gt;Accept Stateful ICMP errors&lt;BR /&gt;Drop and log out of state packets&lt;BR /&gt;Drop and log out of state ICMP packets&lt;BR /&gt;Explicit firewall management rules present&lt;BR /&gt;Accept Remote Access Control connections&lt;BR /&gt;Accept outgoing packets originating from Gateway&lt;BR /&gt;Accept Web and SSH connections for Gateway's administration&lt;BR /&gt;Accept incoming traffic to DHCP and DNS services of gateways&lt;BR /&gt;Accept Dynamic Address modules' outgoing Internet connections&lt;BR /&gt;IPsec VPN&lt;BR /&gt;SSL VPN&lt;BR /&gt;IPS&lt;BR /&gt;Web Security URL Filtering&lt;BR /&gt;Anti-virus and Anti Malware&lt;BR /&gt;Anti-Spam and Email Security&lt;BR /&gt;Acceleration and Clustering&lt;BR /&gt;Voice over IP&lt;BR /&gt;Data loss Prevention&lt;BR /&gt;Application Control&lt;BR /&gt;Logging&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, the list is long, but if you could help me I will be grateful to you, thanks..!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 07:09:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/64701#M13250</guid>
      <dc:creator>kapuranirudh</dc:creator>
      <dc:date>2019-10-10T07:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in preparing benchmark documents for Checkpoint firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/64864#M13255</link>
      <description>It’s not clear what you mean by “Risk Factors” here.&lt;BR /&gt;This also looks like a mix of Global Properties, OS settings, etc.&lt;BR /&gt;Can you provide some context around the question?</description>
      <pubDate>Sat, 12 Oct 2019 01:30:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/64864#M13255</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-12T01:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in preparing benchmark documents for Checkpoint firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/65565#M13387</link>
      <description>Hi, Thanks for your reply, I wanted to know what happens if the above particular settings are not configured on a checkpoint firewall, then what could be the risk to the firewall. Example: If "Password Minimum length is set" is not followed then "anyone can easily guess the passwords and control the incoming and outgoing traffic to a firewall."&lt;BR /&gt;&lt;BR /&gt;As I am a novice in this field so I hope now I am able to explain my question properly to you. Thanks</description>
      <pubDate>Tue, 22 Oct 2019 12:29:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/65565#M13387</guid>
      <dc:creator>kapuranirudh</dc:creator>
      <dc:date>2019-10-22T12:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in preparing benchmark documents for Checkpoint firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/65568#M13388</link>
      <description>&lt;P&gt;You really have just put together a confusing mix of buzzwords, but no &lt;SPAN&gt; benchmark conditions&lt;/SPAN&gt;:&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;Ensure ... is something to do to meet standards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- VPN packet handling errors are not&amp;nbsp;RISK factors&lt;BR /&gt;- VPN configuration &amp;amp; key exchange errors are not&amp;nbsp;RISK factors&lt;BR /&gt;- IP Options drop are not&amp;nbsp;RISK factors&lt;BR /&gt;- File Transfer Protocol (FTP) is no RISK factors if configured&amp;nbsp;appropriately&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;IPsec VPN is a SW blade, no RISK factor&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- SSL VPN is a SW blade, no RISK factor&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- IPS&amp;nbsp;is a SW blade, no RISK factor&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Also&amp;nbsp;&lt;SPAN&gt;a SW blade, no RISK factor is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;URL Filtering&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Anti-virus and Anti Malware&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Anti-Spam and Email Security&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Acceleration and Clustering&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Data loss Prevention&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Application Control&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Logging&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I would rather suggest doing the CCSA and the CCSE certification, study the documentation and suddenly, most of it may be very clear to you&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt; !&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 13:21:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/65568#M13388</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-22T13:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in preparing benchmark documents for Checkpoint firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/65569#M13389</link>
      <description>&lt;P&gt;Many points of this list are just configurations that achieve certain functionality, therefore many of them don't propose a risk if you don't set them up&lt;/P&gt;&lt;P&gt;For example: Dynamic routing, IPSec VPN, among others.&lt;/P&gt;&lt;P&gt;You should focus on risk of not using security features such as IPS or potential security risks by using Dynamic routing.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 13:17:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-help-in-preparing-benchmark-documents-for-Checkpoint/m-p/65569#M13389</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-22T13:17:09Z</dc:date>
    </item>
  </channel>
</rss>

