<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpSec Integration with QRader in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29093#M5960</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The opsec is done with the management/log server, not the gateways. Create the OPSEC object, check LEA as service and define your QRadar host, then initialize SIC.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Jan 2019 11:51:28 GMT</pubDate>
    <dc:creator>Alex-</dc:creator>
    <dc:date>2019-01-31T11:51:28Z</dc:date>
    <item>
      <title>OpSec Integration with QRader</title>
      <link>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29092#M5959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We need to configure Opsec in checkpoint to communicate with QRader.&lt;/P&gt;&lt;P&gt;The question is will this be a unidirectional communication with the QRader or bidirectional ? i read that the certificates are pulled from the checkpoint, in&amp;nbsp; that case are these certificates pulled from the management server or the Gateways ? So do i need to enable port access from QRader to&amp;nbsp; Management Server or the Gateways ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Environment Details : VSX Cluster, Gaia R80.10 ,SmartConsole&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 08:47:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29092#M5959</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2019-01-31T08:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: OpSec Integration with QRader</title>
      <link>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29093#M5960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The opsec is done with the management/log server, not the gateways. Create the OPSEC object, check LEA as service and define your QRadar host, then initialize SIC.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 11:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29093#M5960</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2019-01-31T11:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: OpSec Integration with QRader</title>
      <link>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29094#M5961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See: &lt;A href="https://community.checkpoint.com/message/8902-re-does-r8010-supports-opsec" target="_blank"&gt;https://community.checkpoint.com/message/8902-re-does-r8010-supports-opsec&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:15:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29094#M5961</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-06-21T09:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: OpSec Integration with QRader</title>
      <link>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29095#M5962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks...so after this i need to copy the content of Communication: DN field into QRader ?&lt;/P&gt;&lt;P&gt;Also, bidirectional ACL will be applied for Qrader -&amp;gt; Management Server IP on the required Port ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 15:15:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29095#M5962</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2019-01-31T15:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: OpSec Integration with QRader</title>
      <link>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29096#M5963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #333333; border: 0px;"&gt;I remember this being unnecessarily more difficult than other OPSEC integrations I had performed.&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Here is a screenshot that may help you get started. The trick was obtaining the correct DN's for the QRadar OPSEC object and the SMS.&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;The OPSEC DN is easy enough to obtain. Just edit the properties of the object and copy+paste the DN next to the Communication button.&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;The SMS was a little trickier unless someone knows I shortcut I don't. In R77, I think you used to be able to just see this by viewing the properties of the SMS and clicking the Communication button. This seems to be a bit different in R80. The quickest way I was able to find was to enable the ICA Portal. From the CLI of your SMS, run:&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;EM&gt;&lt;STRONG&gt;cpca_client set_mgmt_tool on&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px;"&gt;Then browse to&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;http://&amp;lt;ip of your SMS&amp;gt;:18265&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px;"&gt;You should be able to find the DN of the SMS there. Once you have it, turn the ICA Portal back off:&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;cpca_client set_mgmt_tool off&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78063_qradar.jpg" /&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;For some reason, I had to manually copy the certificate from my SMS to the QRadar server. I think this was because the two servers were on different LANs without the proper Firewall rules to allow the ICA communication. Assuming you have that, you should be able to skip the part about specifying a file name for the cert.&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;BR /&gt;Since the procedure is different from here, I found these steps in a different Check Mates thread on this topic. Hopefully, this should be accurate enough to finish the configuration!&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Specify Certificate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Checked&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Certificate Authority IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;IP of your management server&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Pull Certificate Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;the shared / trusted SIC secret you specified in OBSEC object&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Checked&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Target Collector&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;which QRADAR appliance do you want to reach out to the Log Server&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Coalescing Events&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Checked&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Store Event Payload&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Checked&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Log Source Extension&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;I left this blank&lt;/P&gt;&lt;P style="color: #333333; border: 0px;"&gt;Select QRadar Groups&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Check the group you want.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 15:16:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29096#M5963</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2019-01-31T15:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: OpSec Integration with QRader</title>
      <link>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29097#M5964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using GUIDBEdit is another option (&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk61833&lt;/SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61833" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61833"&gt;How to find the SIC DN name of Security Management for an OPSEC client configuration&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 17:31:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29097#M5964</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2019-01-31T17:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: OpSec Integration with QRader</title>
      <link>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29098#M5965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any reason you're using LEA to export logs instead of Log Exporter?&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/message/16349"&gt;Log Exporter guide&lt;/A&gt;‌&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 20:21:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29098#M5965</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-01T20:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: OpSec Integration with QRader</title>
      <link>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29099#M5966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it's definitely an option, here is QRadar's guide&amp;nbsp;in the IBM Knowledge Center:&amp;nbsp;&lt;A class="link-titled" href="https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/c_DSM_guide_Checkpoint_LEEF.html" title="https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/c_DSM_guide_Checkpoint_LEEF.html"&gt;Configure Check Point Log Exporter to forward LEEF events to QRadar by using syslog&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 21:22:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/OpSec-Integration-with-QRader/m-p/29099#M5966</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2019-02-01T21:22:19Z</dc:date>
    </item>
  </channel>
</rss>

