- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: HCP - Threat Prevention Protections impact
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HCP - Threat Prevention Protections impact
Hi All,
When I'm looking to my HCP report under Threat Prevention > Protections > Protections Impact I see a lot of 'Applictions' instead of IPS.
The applications that are in the report aren't configured in any rule. Is there a way to finetune this?
SmartConsole Extensions Threat Prevention
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Adding @Andy_Yelnik
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you have an APCL/URLF rule with Service & Application set to "Any" also with Detailed Logging set (such as the cleanup rule), overhead will be expended identifying & logging these applications which is what you are seeing in hcp. You can set Track for these rules to just "Log" but the specific applications matching this rule will no longer be detected and logged.
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Timothy,
The only rules that these applications can hit are the 'Cleanup Rules' with action Drop and track Log.
We've 1 other rule to block traffic to internet with action Reject but only track Log
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a way to find the rule(s) that is/are responsible for this traffic?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I also saw that in web version of HCP for R81.20, but did not pay much attention to it.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
which url to consult web version of HCP result?
thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check here.
/var/log/hcp/last/...*.tgz
download the file and open with a brower after extracting .tgz contents
[ ]´s
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes i know
i mean, i remember something like https://fw-ip/hcp ... but it doesn't work
i dunno why is not documented in official SK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is documented in jumbo takes:
PRJ-42453, |
HCP |
NEW: HCP report is now available in WebUI. To access it, use the link: https://<Security Gateway IP address>/hcp. |
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You have the correct URL, but that web-based functionality is only supported for later R81.10 Jumbo HFAs and R81.20+. Here is the relevant page from my Gateway Performance Optimization Course mentioning this:
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i'm on r81.20, isn't working.... maybe the problem is related to Web portal on port 443...
anyway, i think is something to be added in official sk https://support.checkpoint.com/results/sk/sk171436
thank you all
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Trust me, it works, I tested it on R81.20 many times...message me, I can show you via remote if needed.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Technically, like any "sub" domain if you will (for the lack of better term), would go like that, you need custom web UI port for it to work...so https://w.z.y.z:customport/hcp, so in my case it was https://172.16.10.249:4434/hcp
I also ran it on Azure fw lab, but page is sort of "scrambled", but it could be since its cloud fw, on prem works 100% of the time.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Never mind, got it...just did not wait long enough lol
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Tim,
Just to let you know that SK180368 is marked as deleted in the support center.
"
Deleted
This SK no longer exists
"
There is this:
"
Dr. Spark
With the Dr. Spark feature, you can check the Quantum Spark Appliance performance, sizing and health status.
|
Note - The Dr. Spark feature is available as a separate tab starting from R81.10.08. In earlier versions, the Dr. Spark buttons are available on the Using System Tools page. |
"
Can you please share with me the hcp argument/command for a TP health check?
I thought it was in the CTPS courseware but a Kortext search does not find hcp.
EDIT
Never mind, I found it on page 457 🙂
END OF EDIT
Regards,
Don
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are 100% right, the sk has been removed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This information now exists in the official guides (thus why the SK was deleted).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It definitely works, I tested it in the lab many times. Make sure to add custom port for web UI if it exists
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just ran it, below is my example, its simply the web fqdn, you add hcp on "top" of web UI
Andy
