Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Piet_vd_Maas
Contributor

HCP - Threat Prevention Protections impact

Hi All,

When I'm looking to my HCP report under Threat Prevention > Protections > Protections Impact I see a lot of 'Applictions' instead of IPS.

The applications that are in the report aren't configured in any rule. Is there a way to finetune this?

 

SmartConsole Extensions Threat Prevention 

CCSM - CCTE - CCVS - CCMS
0 Kudos
19 Replies
Tal_Paz-Fridman
Employee
Employee

Adding @Andy_Yelnik 

0 Kudos
Timothy_Hall
Legend Legend
Legend

If you have an APCL/URLF rule with Service & Application set to "Any" also with Detailed Logging set (such as the cleanup rule), overhead will be expended identifying & logging these applications which is what you are seeing in hcp.  You can set Track for these rules to just "Log" but the specific applications matching this rule will no longer be detected and logged.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
Piet_vd_Maas
Contributor

Hi Timothy,

The only rules that these applications can hit are the 'Cleanup Rules' with action Drop and track Log.

We've 1 other rule to block traffic to internet with action Reject but only track Log

CCSM - CCTE - CCVS - CCMS
0 Kudos
Piet_vd_Maas
Contributor

Is there a way to find the rule(s) that is/are responsible for this traffic?

CCSM - CCTE - CCVS - CCMS
0 Kudos
the_rock
Legend
Legend

I also saw that in web version of HCP for R81.20, but did not pay much attention to it.

Andy

0 Kudos
CheckPointerXL
Advisor
Advisor

which url to consult web version of HCP  result?

thanks

0 Kudos
rrbranco
Collaborator
Collaborator

Check here.

 

/var/log/hcp/last/...*.tgz 

 

download the file and open with a brower after extracting .tgz contents

 

 

[ ]´s

 

0 Kudos
CheckPointerXL
Advisor
Advisor

yes i know

i mean, i remember something like https://fw-ip/hcp ... but it doesn't work

 

i dunno why is not documented in official SK

0 Kudos
Lesley
Leader Leader
Leader

It is documented in jumbo takes:

PRJ-42453,
PMTR-77024

HCP

NEW: HCP report is now available in WebUI. To access it, use the link: https://<Security Gateway IP address>/hcp.

-------
If you like this post please give a thumbs up(kudo)! 🙂
(1)
Timothy_Hall
Legend Legend
Legend

You have the correct URL, but that web-based functionality is only supported for later R81.10 Jumbo HFAs and R81.20+.  Here is the relevant page from my Gateway Performance Optimization Course mentioning this:

hcpweb.png

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
(1)
CheckPointerXL
Advisor
Advisor

i'm on r81.20, isn't working.... maybe the problem is related to Web portal on port 443...

anyway, i think is something to be added in official sk https://support.checkpoint.com/results/sk/sk171436

thank you all

0 Kudos
the_rock
Legend
Legend

Trust me, it works, I tested it on R81.20 many times...message me, I can show you via remote if needed.

Andy

the_rock
Legend
Legend

Technically, like any "sub" domain if you will (for the lack of better term), would go like that, you need custom web UI port for it to work...so https://w.z.y.z:customport/hcp, so in my case it was https://172.16.10.249:4434/hcp

I also ran it on Azure fw lab, but page is sort of "scrambled", but it could be since its cloud fw, on prem works 100% of the time.

Best,

Andy

0 Kudos
the_rock
Legend
Legend

Never mind, got it...just did not wait long enough lol

Best,

Andy

 

 

Screenshot_1.png

 

 

0 Kudos
Don_Paterson
Advisor
Advisor

Hi Tim,

Just to let you know that SK180368 is marked as deleted in the support center.
"

Deleted

This SK no longer exists

"

There is this:

https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/Dr...

"

Dr. Spark

With the Dr. Spark feature, you can check the Quantum Spark Appliance performance, sizing and health status.

Don_Paterson_0-1720164600551.png

 

Note - The Dr. Spark feature is available as a separate tab starting from R81.10.08. In earlier versions, the Dr. Spark buttons are available on the Using System Tools page.

"

Can you please share with me the hcp argument/command for a TP health check?

I thought it was in the CTPS courseware but a Kortext search does not find hcp.

EDIT

Never mind, I found it on page 457 🙂

END OF EDIT 

Regards,

Don

0 Kudos
the_rock
Legend
Legend

You are 100% right, the sk has been removed.

0 Kudos
PhoneBoy
Admin
Admin

This information now exists in the official guides (thus why the SK was deleted).

the_rock
Legend
Legend

It definitely works, I tested it in the lab many times. Make sure to add custom port for web UI if it exists

ie https://x.x.x.x:4434/hcp

Andy

0 Kudos
the_rock
Legend
Legend

I just ran it, below is my example, its simply the web fqdn, you add hcp on "top" of web UI

Andy

 

Screenshot_1.png

0 Kudos
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events