Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
FrancisD
Explorer

OPSEC - TrendMicro Vision One integration

We´re trying to integrate the Trend Micro Vision One solution (distribution of IOCs IPs) via SAM.

Created two OPSEC aplication objects, one for each internal gateway (two different DCs). Configured trend micro to distribute the info to the manager. I can see packets arriving the manager through TCPDUMP but nothing shows up in the Smartview Monitor.

On Trend Console there´s a message: "The maximum file size of the SAM database has been reached. Contact the Check Point administrator. (Error code: 10271)".

Trend Micro GW is a server LAN based, same network as the Smart Console.

 

OPSEC object config:

Host: [trendmicro GW IP]

Vendor: user defined

client entities selected: SAM

Communication Status: Trust established

 

Trend micro gw config:

server address: [SmartConsole IP]

Port: 18183

OPSEC app name: same as CKP object

SIC password: same as CKP object

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

The SAM rule database can only be a certain size and it has been exceeded.
Follow from Step 6 onward to adjust this: https://support.checkpoint.com/results/sk/sk97306

0 Kudos
FrancisD
Explorer

Is there a difference from doing it from the SmartDashboard?

Before posting I tried that with Smart Console. Same results.

0 Kudos
PhoneBoy
Admin
Admin

Please show exactly what you configured...with screenshots.
Also, please state the version/JHF of the gateways and management.

0 Kudos
FrancisD
Explorer

Manager R80.40

Gw Maestro R80.30SP

trend-config.PNGtrust.PNGGW-SAM-size.PNGobject.PNG

0 Kudos
PhoneBoy
Admin
Admin

You can try to troubleshoot using the steps here: https://support.checkpoint.com/results/sk/sk117087 
This will most likely require TAC assistance, possibly from Trend Micro as well.
https://help.checkpoint.com 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events