- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
I have a Checkpoint Log Server that is the center point of logs for 6 firewalls. I've setup a LEA connection to that server from a SOC log collection appliance, TCP 18186, which works fine, and another one to a QRadar SIEM 18185 which doesn't work at all. I've restarted services and rebooted, the LogServer just wont listen on the port. I've confirmed this with netstat. Attached is the fwopsec file from the Checkpoint logs server. Any help is appreciated.
Thanks,
Justin
My question is: why do you need to use multiple LEA ports?
Particularly when they are both unauthenticated?
The only place I've seen two different LEA ports used is when one of them is authenticated, the other is not.
Something like in this SK: Configuring a Log Server R76 and lower to work with both SmartEvent component and an OPSEC LEA serve...
I don't believe you can do two unauthenticated LEA ports.
https://community.checkpoint.com/people/bbent09791668-5ef8-377b-845e-545aff695211?
My question is: why do you need to use multiple LEA ports?
Particularly when they are both unauthenticated?
The only place I've seen two different LEA ports used is when one of them is authenticated, the other is not.
Something like in this SK: Configuring a Log Server R76 and lower to work with both SmartEvent component and an OPSEC LEA serve...
I don't believe you can do two unauthenticated LEA ports.
https://community.checkpoint.com/people/bbent09791668-5ef8-377b-845e-545aff695211?
Thanks for the reply Dameon. I didn't realize that I could point two log sources at the same LEA instance. When you say "unauthenticated", I mean, they do exchange certificates and SIC information. Would you say they are still unauthenticated in that instance ?
Thanks again,
Justin
I mean unauthenticated.
This is based on what it says in sk89620 and the screenshot of your fwopsec.conf says.
You probably want to change the line to auth_port instead of just port if you want SIC authentication ![]()
Note that LEA has been multi-threaded (and able to support multiple endpoints connecting) since R77.
What Dameon said 🙂 Would just add that if both do SIC, then there's no need for the fwopsec.conf edits. Use the defaults and have them connect on the same port 18184. Will simplify things when you do an upgrade.
Thanks for the many responses. Couldn't get it to work on 18184. I did a tcpdump and currently traffic between log and management server exist on that port. I got it work with 18186 but most of the pertinent fields come across as *** Confidential *** . I'm assuming perhaps checkpoint doesn't like to send this info across the wire in the clear ?
Going to try 18184 again.
Second try worked with 18184, going to change my other log source as well. Thanks for all the help. I haven't worked on Checkpoints for 10+ years back when they were on Nokias so I am more than a little rusty.
This guide was helpful on the QRADAR side.
Great to hear ![]()
I still have a few Nokia boxes at my house from back in the days when I worked there.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY