<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMP Portal configuring remote syslog hosts in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMP-Portal-configuring-remote-syslog-hosts/m-p/75507#M3049</link>
    <description>&lt;P&gt;oh and.. uh.. the default gaia web portal is enabled on those. Again seems.. um.. strange.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Feb 2020 15:27:06 GMT</pubDate>
    <dc:creator>John_Fleming</dc:creator>
    <dc:date>2020-02-17T15:27:06Z</dc:date>
    <item>
      <title>SMP Portal configuring remote syslog hosts</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMP-Portal-configuring-remote-syslog-hosts/m-p/75438#M3046</link>
      <description>&lt;P&gt;So this seems.. odd.. I signed up my 1550 into the SMP portal, which i'm not sure if i'm digging so far but thats another story.&lt;/P&gt;&lt;P&gt;I was poking around in syslog configuration and ran across this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ModLoad imuxsock.so&lt;BR /&gt;$LocalHostName |stuff|&lt;BR /&gt;$DefaultNetstreamDriverCAFile /opt/fw1/bin/ca-bundle.crt&lt;BR /&gt;$ActionSendStreamDriver ossl&lt;BR /&gt;$ActionSendStreamDriverMode 1&lt;BR /&gt;$ActionSendStreamDriverAuthMode x509/name&lt;BR /&gt;$ActionSendStreamDriverPermittedPeer *.Syslog&lt;BR /&gt;$template format,"%$YEAR% %timegenerated% %HOSTNAME% %syslogfacility-text%.%syslogpriority-text% %programname%: %msg%\n"&lt;BR /&gt;$outchannel msg_rotation,/var/log/messages, 204800,/pfrm2.0/bin/log_gzip.sh /var/log/messages&lt;BR /&gt;$outchannel ntf_rotation,/logs/notifications, 204800,/pfrm2.0/bin/log_gzip.sh /logs/notifications&lt;BR /&gt;*.info;mail.!* :omfile:$msg_rotation;format&lt;BR /&gt;mail.info :omfile:$ntf_rotation;format&lt;BR /&gt;*.info;mail.!* @mysyslogserver:514&lt;BR /&gt;*.info;mail.!* @209.87.212.13:514&lt;BR /&gt;*.info;mail.!* @209.87.212.16:514&lt;BR /&gt;*.info;mail.!* @209.87.212.14:514&lt;BR /&gt;*.info;mail.!* @209.87.212.15:514&lt;BR /&gt;*.info;mail.!* @209.87.222.192:514&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I never configured the firewall to send syslog events to those addresses. I get the need for logs but OS logs? Again maybe its part of SMP and thats fine I guess.. but udp syslog? That just seems a bit strange. I sure hope there is some dynamic filtering going on and that those addresses aren't just open to the public at large.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 09:11:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMP-Portal-configuring-remote-syslog-hosts/m-p/75438#M3046</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-17T09:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: SMP Portal configuring remote syslog hosts</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMP-Portal-configuring-remote-syslog-hosts/m-p/75507#M3049</link>
      <description>&lt;P&gt;oh and.. uh.. the default gaia web portal is enabled on those. Again seems.. um.. strange.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 15:27:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMP-Portal-configuring-remote-syslog-hosts/m-p/75507#M3049</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-17T15:27:06Z</dc:date>
    </item>
  </channel>
</rss>

