Hi
Firewall best practice suggests that every rule on the firewall should have a bunch of meta-data associated with it, like who requested it, who approved or implemented it, when it was implemented, and perhaps change tickets and audit trails of changes to the rule over time.
Checkpoint R80 does all of that, but the next stage of an audit suggests that each rule be reviewed periodically to make sure it is still necessary, that the systems it was created to support still exist or operate in the same way, and so on.
I understand 3rd party tools like Tufin offer this kind of functionality, but is there is something in Checkpoint in the audit features or compliance maybe that can list all the rules that are say 3 years old and should be reviewed now, and would allow the 'review' clock to be reset at that time?
Am I missing something obvious?
Thanks