- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: KPI FW and IPS drops
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
KPI FW and IPS drops
Hello,
I have a smartcenter R81.10 in latest version and with Quantum and SMB firewalls.
I need to know the number of FW (Access Control and Firewall) and IPS drops. Just a daily and monthly value. This will give trends and show which sites are receiving the most attacks, for example.
I'm really having trouble finding this information.
Can anyone help me?
Kind regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have a SmartEvent license?
This is likely needed to get this information unless you want to export the logs elsewhere to do the count.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I have the license.
Can you explain how to get the information from SmartEvent?
Kind regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Create a new View (tap the plus in the tab bar, tap Views, the New > New View, give it a name and select Access Control).
Then add a widget something like:
(Note if you are using App Control/URL Filtering, you may wish to add those blades also)
Something similar can be done for IPS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks.
It gives several possibilities, I did the counter, but the value is very low, even over 1 month, it does not exceed 2, on the same filter as you.
If I want to have the daily value. What to do?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Set the exact timeframe you want in the view (done in the upper left of the screen).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's not great, I thought it was possible to have a graph or table showing the daily values and not select each day one by one.
Moreover, even with this filter, the value does not change.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are other widget methods that might work better here for your use case.
I recommend trying them out and seeing what works for you.
As for the counting issue, I suspect the issue is that your drops are not being indexed by SmartEvent.
Please ensure all drop rules include "Session" logging per: https://support.checkpoint.com/results/sk/sk150452
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sounds like you need to enable smart event to get this.
Andy
