Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Moudar
Advisor

Administrator daily routines

Hi,

In this post, I'm embarking on a journey to uncover the daily habits of firewall administrators! My goal is to not only equip myself but also empower others reading this to become more confident and effective guardians of our networks.

1-What daily security checks should I perform as a Checkpoint firewall admin to identify potential attacks?

2-Seeking insights: What elements and daily checks should be included in an expert's Checkpoint firewall security report?

3-What is the most important thing that you need to check very often to make sure that your network is safe?

4-In your experience, what continuous monitoring practice provides the most actionable intelligence for securing a network?

5-What are your daily routines as a firewall administrator?

6-I'm curious about the daily practices of a firewall administrator. What specific checks and configurations do you prioritize?

Any more ideas are welcome! Don't hesitate to share any additional thoughts or suggestions you have!

 

/Moudar

7 Replies
the_rock
Legend
Legend

I will see if I can find a good doc customer sent me while back about this, so glad you made this post, absolutely relevant.

Andy

0 Kudos
Moudar
Advisor

Excited to dive into the linked resources, but wouldn't it be amazing to combine that with your personal wisdom? If you're willing to share some of your daily habits and how they've shaped your work, I'd be incredibly grateful!

0 Kudos
the_rock
Legend
Legend

I would be happy to share if I were fw admin myself, which Im not lol

Best,

Andy

0 Kudos
spottex
Collaborator

We have a new engineer in our team who has updated a nightly script running on a MDM which checks all the GW's to see if backups have run. It now also looks for core dumps, snapshots the hosts resources and uptime, gets installed hotfixes which reports in a html table via email every morning. 
He has added secondary emails to the Service Desk to log a support ticket to the Security Team for each backup that fails and if any core dumps are found. 

Moudar
Advisor

The automation of processes is a hot topic these days, and I'm definitely intrigued! Could you delve deeper into it, particularly exploring the different tools we could leverage? Specifically, I'm curious about using Ansible scripts, Python scripts, or even leveraging Management APIs. The ideas of what to automate are most important, hence, additional insights into potential automation targets would be immensely valuable.

0 Kudos
spottex
Collaborator

I wrote the first one that just checked the backups via "show backups status" using HeikoAnkenbrand's earlier version of gw_multi_commands
REF: https://community.checkpoint.com/t5/Scripts/GAIA-Easy-execute-CLI-commands-on-all-gateways-simultane...
It was ok for a quick look at backups every morning.

I wont share the new script as it will become added value for our clients.
But for an overview it is BASH with if/then and awk
* mgmt_cli to extract the domains from the MDM and then their gateways
* $CPDIR/bin/cprid_util to run remote commands on the GW's which is using SIC to connect
* Output file is populated with all the data and formats it to HTML
* More if/thens to create emails to the services desk
* Uses an internal smtp relay to forward the email

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events