- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Checkpoint with Thousandeyes
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint with Thousandeyes
Anyone integrated thousandeyes with Checkpoint? Looks like there is some incompatibility between SNMP cipher?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I found a post from last year where Phoneboy indicated he was not aware of any known issues. I checked Thousandeyes documentation, could not find anything specific either.
Do you have any link or statement about this?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@the_rock these are the options that Thousandeyes support for SNMPV3 and I have tried all the options and while capturing packet from checkpoint I can see packets coming through and also moving from i > I .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So none of them work? 😞
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sadly noone of them worked.
I was wondering if I could find some expert here who has deployed thousandeyes with checkpoint.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
K, lets wait and see if someone might have an idea.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As of R81.20, Check Point only supports usmHMAC192SHA256AuthProtocol and usmHMAC384SHA512AuthProtocol for authentication (RFC 7860), and DES (RFC 3414), AES-128 (RFC 3826), or AES-256 (non-standard) for privacy. It definitely works with Thousandeyes. I would go with usmHMAC384SHA512AuthProtocol and AES-128.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is no AES-128 option in Checkpoint and I am using privacy-protocol AES256 authentication-protocol SHA512
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would verify with TAC on this.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@ma_gorkhali wrote:
There is no AES-128 option in Checkpoint and I am using privacy-protocol AES256 authentication-protocol SHA512
There absolutely is an AES-128 option, they just leave off the key length (128 bits is the only RFC-compliant AES key length):
[Expert@MyManagement]# fwm ver
This is Check Point Security Management Server R81.20 - Build 017
[Expert@MyManagement]# cpinfo -y fw1
This is Check Point CPinfo Build 914000250 for GAIA
[FW1]
HOTFIX_INEXT_NANO_EGG_AUTOUPDATE
HOTFIX_R81_20_JUMBO_HF_MAIN Take: 92
HOTFIX_WEBCONSOLE_AUTOUPDATE
HOTFIX_GOT_MGMT_AUTOUPDATE
HOTFIX_NGM_DOCTOR_AUTOUPDATE
HOTFIX_VCE_R81_20_AUTOUPDATE
HOTFIX_GOT_TPCONF_MGMT_AUTOUPDATE
HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE
FW1 build number:
This is Check Point Security Management Server R81.20 - Build 017
This is Check Point's software version R81.20 - Build 043
[Expert@MyManagement]# clish
MyManagement> add snmp usm user NewUser security-level authPriv auth-pass-phrase vpn123 privacy-pass-phrase vpn123 privacy-protocol
DES AES AES256
MyManagement> add snmp usm user NewUser security-level authPriv auth-pass-phrase vpn123 privacy-pass-phrase vpn123 privacy-protocol AES authentication-protocol
SHA256 SHA512
MyManagement> add snmp usm user NewUser security-level authPriv auth-pass-phrase vpn123 privacy-pass-phrase vpn123 privacy-protocol AES authentication-protocol SHA
