- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Create firewall alert
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Create firewall alert
Good morning!
I would like to create a firewall alert as follows:
When a user with a personal laptop connects to our network and tries to access the internet, the firewall should block it and notify us, generating an alert for this connection.
Is it possible to create this type of alert on the firewall?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The answer here has 2 steps:
First step - you need the specific traffic to be matched on access policy rule. Here I agree with @Chris_Atkinson , IDA is the way to go here IMO but nothing specific is required except matching a rule.
Second step - enable alerts on the rule and define the alert.
1. Right click "Track" column on the specific rule -> Alert -> Choose alert type (See 1.png).
2. From main menu, go to Global Properties (See 2.png).
3. Navigate to Log and Alert -> Alerts. For each alert you can choose if you want to send alerts to SmartView Monitor, run script or both (See 3.png).
From here you can choose whatever method you see fit to your needs. If you want to define email alert you can use the following SK: https://support.checkpoint.com/results/sk/sk25941
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Conceptually, but more information is needed here:
- Do you already utilize the Identity Awareness Agent?
- Do you have integration with another NAC solution such as Cisco ISE?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The answer here has 2 steps:
First step - you need the specific traffic to be matched on access policy rule. Here I agree with @Chris_Atkinson , IDA is the way to go here IMO but nothing specific is required except matching a rule.
Second step - enable alerts on the rule and define the alert.
1. Right click "Track" column on the specific rule -> Alert -> Choose alert type (See 1.png).
2. From main menu, go to Global Properties (See 2.png).
3. Navigate to Log and Alert -> Alerts. For each alert you can choose if you want to send alerts to SmartView Monitor, run script or both (See 3.png).
From here you can choose whatever method you see fit to your needs. If you want to define email alert you can use the following SK: https://support.checkpoint.com/results/sk/sk25941
