- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Compliance blade missing checks
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Compliance blade missing checks
Hi Everyone,
We have a HA MDS server running R81.20 with Jumbo HFA take 92. The MDS server has 5 domains. We're running Compliance blade.
Each domain has 85 Security best practice checks, but 1 domain has only 80 checks.
Following 5 checks are missing
FW174 Check that Access Control rules do not contain 'Any' in 'Source', and 'Accept' or 'Ask' in 'Action'
FW175 Check that Access Control rules do not contain 'Any' in 'Destination', and 'Accept' or 'Ask' in 'Action'
FW176 Check that Access Control rules do not contain 'Any' in 'Services and Applications', and 'Accept' or 'Ask' in 'Action'
FW177 Check that there are no temporary Access Control rules (based on the 'Name' column)
FW178 Check that there are no temporary Access Control rules (based on the 'Comments' column)
It looks like above check have been added to Jumbo Take 26, but MDS is on Take 92 and the other domains are all good.
This check are very important for me, so I'm trying to understand if it is possible to add them manualy or run some kind of update.
The second question is: Do you know how many checks all together should be in the Security Best Practice compliance?
Regards
Libor
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I suspect you're going to need to consult with TAC to understand why one domain isn't showing the relevant Compliance rules.
On the second question, not sure, but maybe @RobertoQ knows.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is a long shot:
Compliance blade is missing objects in Overview:
On the Compliance server run the following in expert mode:
[Expert@HostName:0]# interpreter full_scan reset_mode
By the way if you download a fresh template from here:
https://community.checkpoint.com/t5/Compliance/bd-p/Compliance
Any would do, do you also see difference in those reports?
Easy to do, download and import and done.
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for this, interpreter full_scan reset_mode didn't help and the link provided does not include template for CheckPoint Security Best Practice as far as I know,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
In R81.20 Compliance you should have 280 best practices. Can you please check on your problematic domain Compliance DB if you can find the missing BPs? Also, I would suggest running another manual run on this Domain. Go to the Manage & Settings view > Blades > Compliance > Settings > click the Rescan button. You cannot perform any actions in the Compliance tab while the scan runs. Let us know if it helps. If not, I strongly recommend opening a support ticket.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
That's very helpful, Is there a full list you can share? I ran manual scan couple of times already, no luck. I'm going to raise a case. Thanks for your help
Libor
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When you open a ticket ask as well to get a list of all BPs. Good luck !
