<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Commands for baseline security in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138286#M24641</link>
    <description>&lt;P&gt;It only exists on the SMS:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;# more $FWDIR/conf/objects_5_0.C | grep rlogin_max_auth_allowed&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin_max_auth_allowed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt; (3)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Which AlgoSec product and version are you using, looks rather old from the details you mention...&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jan 2022 14:28:11 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2022-01-12T14:28:11Z</dc:date>
    <item>
      <title>Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138241#M24616</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;I'm working on the firewall's security baseline using the algosec tool, where one of the requirements is to execute the commands below:&lt;/P&gt;&lt;P&gt;more $FWDIR/conf/objects.C | grep rlogin_max_auth_allowed&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;more $FWDIR/conf/objects.C | grep telnet_max_auth_allowed&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As for the objects.C file was found, but not the part of "rlogin_max_auth_allowed" and telnet_max_auth_allowed&lt;/P&gt;&lt;P&gt;Do you know where to find these parameters?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 11:26:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138241#M24616</guid>
      <dc:creator>Paulo_Feitosa</dc:creator>
      <dc:date>2022-01-12T11:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138245#M24618</link>
      <description>&lt;P&gt;You are looking in the wrong file. Use&amp;nbsp;&lt;SPAN&gt;$FWDIR/conf/objects_5_0.C&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, correct me if I am wrong, but this guidance is for R77 and below. What version of Check Point are you running?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 11:45:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138245#M24618</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-01-12T11:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138246#M24619</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Nice to get output, but what is the reason? On a firewall module R80.40 i get:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;:comments ("Remote login (&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;)")&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On R81.10 SMS:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[Expert@SMS8110:0]# more $FWDIR/conf/objects.C | grep rlogin&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_transparent_server_connection (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_transparent_server_connection (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_transparent_server_connection (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_transparent_server_connection (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_max_auth_allowed (3)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_msg ()&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_use_fwnetso (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[Expert@SMS8110:0]# more $FWDIR/conf/objects.C | grep telnet&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_transparent_server_connection (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_transparent_server_connection (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_transparent_server_connection (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_transparent_server_connection (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; : (FW1_clntauth_&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; : (&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; : FW1_clntauth_&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; : &lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; : &lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :handler (&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_env_cmd_block)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; : (solaris_&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :protocol_name (solaris_&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :handler (solaris_&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_block_code)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :handler (&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_reflection_code)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_use_fwnetso (true)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_msg ()&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;telnet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;_max_auth_allowed (3)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 11:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138246#M24619</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-01-12T11:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138249#M24620</link>
      <description>&lt;P&gt;Exactly, algosec asks to check this &lt;SPAN&gt;objects_5_0.C&lt;/SPAN&gt; file but it doesn't exist, I think.&lt;/P&gt;&lt;P&gt;The files found were:&lt;BR /&gt;objects.C and objects.C_41&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;My firewall version is R80.30&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 11:59:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138249#M24620</guid>
      <dc:creator>Paulo_Feitosa</dc:creator>
      <dc:date>2022-01-12T11:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138250#M24621</link>
      <description>&lt;P&gt;Yes it does exist &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Show us your "ls -la $FWDIR/conf/ grep object" output&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 12:01:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138250#M24621</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-01-12T12:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138251#M24622</link>
      <description>&lt;P&gt;Exactly, the guidance is for the MGMT side here&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 12:02:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138251#M24622</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-01-12T12:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138252#M24623</link>
      <description>&lt;P&gt;On my firewalll don't appear, look:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1-MGT:0]# more $FWDIR/conf/objects.C | grep telnet&lt;BR /&gt;: (FW1_clntauth_telnet&lt;BR /&gt;: FW1_clntauth_telnet&lt;BR /&gt;: (telnet&lt;BR /&gt;: telnet&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 12:06:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138252#M24623</guid>
      <dc:creator>Paulo_Feitosa</dc:creator>
      <dc:date>2022-01-12T12:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138255#M24624</link>
      <description>&lt;P&gt;Are you looking on the GW or management?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 12:27:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138255#M24624</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-01-12T12:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138260#M24625</link>
      <description>&lt;P&gt;-rw-rw---- 1 admin root 0 Sep 23 2020 nku_from_gw&lt;BR /&gt;-rw-r----- 1 admin bin 519 May 12 2020 notify_cert_revocation_vsx.conf&lt;BR /&gt;-rw-r----- 1 admin bin 61245 May 12 2020 objects.C&lt;BR /&gt;-rw-r----- 1 admin bin 36876 May 12 2020 objects.C_41&lt;BR /&gt;-rw-r----- 1 admin bin 3 May 12 2020 observable_overrides.C&lt;BR /&gt;-rw-r----- 1 admin bin 10772 May 12 2020 osfingerprint.eng&lt;BR /&gt;-rw-r----- 1 admin bin 6885 May 12 2020 outbound_and_encrypted.W_vpnddcate&lt;BR /&gt;-rw-r----- 1 admin bin 148878 May 12 2020 parserTopicToSdTopicMappings.C&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 12:54:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138260#M24625</guid>
      <dc:creator>Paulo_Feitosa</dc:creator>
      <dc:date>2022-01-12T12:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138261#M24626</link>
      <description>&lt;P&gt;GW, because algosec collects the command data about the GWs.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 12:57:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138261#M24626</guid>
      <dc:creator>Paulo_Feitosa</dc:creator>
      <dc:date>2022-01-12T12:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138262#M24627</link>
      <description>&lt;P&gt;Did you read my post ? GW only gives the output:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;:comments ("Remote login (&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;)")&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 12:59:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138262#M24627</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-01-12T12:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138264#M24628</link>
      <description>&lt;P&gt;You misread their guidance rules. Those GW parameters are defined on the MGMT server and not directly on those GWs&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 13:00:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138264#M24628</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-01-12T13:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138266#M24629</link>
      <description>&lt;P&gt;AFAIK, Algosec connects to the SMS using OPSEC and communicates using the Management API - but not with the GW...&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 13:03:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138266#M24629</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-01-12T13:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138286#M24641</link>
      <description>&lt;P&gt;It only exists on the SMS:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;# more $FWDIR/conf/objects_5_0.C | grep rlogin_max_auth_allowed&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;rlogin_max_auth_allowed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt; (3)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Which AlgoSec product and version are you using, looks rather old from the details you mention...&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 14:28:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138286#M24641</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-01-12T14:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138299#M24646</link>
      <description>&lt;P&gt;Folks,&lt;/P&gt;&lt;P&gt;In this case, where can I get this data in GW?&lt;/P&gt;&lt;P&gt;more $FWDIR/conf/objects_5_0.C | grep rlogin_max_auth_allowed&lt;/P&gt;&lt;P&gt;more $FWDIR/conf/objects_5_0.C | grep telnet_max_auth_allowed&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 16:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138299#M24646</guid>
      <dc:creator>Paulo_Feitosa</dc:creator>
      <dc:date>2022-01-12T16:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Commands for baseline security</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138302#M24647</link>
      <description>&lt;P&gt;I think we have answered this question three times already &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; These queries should be done on your management server and not on the GWs.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 17:11:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Commands-for-baseline-security/m-p/138302#M24647</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-01-12T17:11:05Z</dc:date>
    </item>
  </channel>
</rss>

