<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule Base &amp;amp; Object Cleanup tools in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166591#M27744</link>
    <description>&lt;P&gt;CP has hit count by rule - so you have to split into one each for&amp;nbsp;&lt;SPAN&gt;multiple hosts or multiple services.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jan 2023 15:00:31 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-01-03T15:00:31Z</dc:date>
    <item>
      <title>Rule Base &amp; Object Cleanup tools</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166586#M27742</link>
      <description>&lt;P&gt;Just looking for some general feedback from others on what is being used for rule base and object cleanup.&amp;nbsp; Are you using an external vendor products, or are there other tools/tricks out there.&lt;BR /&gt;&lt;BR /&gt;We currently use the Tufin Secure Track product,(we did a comparison between Firemon, AlgoSec &amp;amp; Tufin as few years back).&lt;/P&gt;&lt;P&gt;But to be honest we have found that we are not really using most of the features of the Tufin product.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently the main feature(which I really, really&amp;nbsp; like), is the reporting feature that is used for Rulebase &amp;amp; Object Cleanup.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Where if you had a firewall rule with multiple hosts or multiple services in it, it would basically give you a hit count/ per object on the rule.&amp;nbsp; &amp;nbsp; So it was very easy to identify if a particular host or service was getting any hits over a period of time.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;The point is that it makes it very easy to find an object that is unused per rule vs.&amp;nbsp; just being an unused object for the entire policy which can be identified in Smart Console.&lt;BR /&gt;&lt;BR /&gt;If there was an easy way to accomplish this same thing another way, I don't think we would even need Tufin.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Wondering what others are doing, and if there are maybe tools out there that I am not aware of for helping with policy cleanup tasks.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 14:26:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166586#M27742</guid>
      <dc:creator>Scott_Bily</dc:creator>
      <dc:date>2023-01-03T14:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Base &amp; Object Cleanup tools</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166591#M27744</link>
      <description>&lt;P&gt;CP has hit count by rule - so you have to split into one each for&amp;nbsp;&lt;SPAN&gt;multiple hosts or multiple services.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 15:00:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166591#M27744</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-03T15:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Base &amp; Object Cleanup tools</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166595#M27745</link>
      <description>&lt;P&gt;What I always do is export rules in csv format and search for disabled/rules with 0 hits.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 15:26:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166595#M27745</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-03T15:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Base &amp; Object Cleanup tools</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166602#M27747</link>
      <description>&lt;P&gt;That only helps with part of the cleanup journey tho. I'm my example I am not targeting 0 hit rules.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;For example if there are 2 application servers and we were given a list of service(ports) that are required for communications.&amp;nbsp; Tufin would tell us that in that 1 rule, the % of hits per service.&amp;nbsp; So it gave me an easy way to see that&amp;nbsp; FTP as an example was not really being used over a period of time.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;I could create individual rules for the same src &amp;amp; dst hosts for each specific service(port).&amp;nbsp; But I feel that's a little unpractical, and that not how most of our rules were created.&amp;nbsp; &amp;nbsp; &amp;nbsp; And I could also accomplish the same thing by exporting all the logs for a specific rule.&amp;nbsp; &amp;nbsp; But in this method I am limited to my log retention policy which is only about 4 -5 weeks of data.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 16:08:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166602#M27747</guid>
      <dc:creator>Scott_Bily</dc:creator>
      <dc:date>2023-01-03T16:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Base &amp; Object Cleanup tools</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166633#M27752</link>
      <description>&lt;P&gt;Check Point also has a Professional Service called SmartOptimize that I would recommend which would accomplish these tasks and much more. Your account team should be able to provide you specifics if interested.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Service Features are as follows.&lt;/P&gt;
&lt;P&gt;• Detailed reports&lt;BR /&gt;• Recommendations&lt;BR /&gt;provided by expert&lt;BR /&gt;Professional Services&lt;BR /&gt;Consultants&lt;BR /&gt;• Rulebase Optimization&lt;BR /&gt;• Database Optimization&lt;BR /&gt;• System Health&lt;BR /&gt;• Risk analysis&lt;BR /&gt;• In-depth hit count analysis&lt;BR /&gt;• Optional onsite services&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 00:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/166633#M27752</guid>
      <dc:creator>CE_SE</dc:creator>
      <dc:date>2023-01-04T00:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Base &amp; Object Cleanup tools</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/167132#M27775</link>
      <description>&lt;P&gt;Hi. Is that using the APG, or some other Tufin report? Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 14:27:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/167132#M27775</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-01-09T14:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Base &amp; Object Cleanup tools</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/168760#M28071</link>
      <description>&lt;P&gt;A caution with hit counts, are your failover and disaster recovery rules tagged?&amp;nbsp; Has your team specifically addressed&amp;nbsp;this?&amp;nbsp; Examples might be rule or object comments that state they are for DR.&amp;nbsp; You might name the objects with 'dr' in them.&amp;nbsp; Or create a separate rule just for the dr.&amp;nbsp; That way, when you go solving by hitcount=0, you don't delete something that will bite you later.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 15:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-Base-amp-Object-Cleanup-tools/m-p/168760#M28071</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2023-01-23T15:57:41Z</dc:date>
    </item>
  </channel>
</rss>

