- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Gaia Hardening for R81
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gaia Hardening for R81
The document linked below describes the hardening of the Check Point Gaia operating system.
Components that are not necessary for a network security device, or that could cause security vulnerabilities, were removed.
Check Point Gaia R81 is based on Red Hat 7.6 version and the Linux kernel 3.10.0-957.
The applications removed from the operating system include X Windows, Office applications, games, and many other applications that are irrelevant to Firewall operations.
The document linked below describes the remaining packages and modifications to the system.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
But there are still a lot of packages missing.
For example openssl. This package has been modified by Check Point.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm in this process and also using the following as reference:
https://www.cisecurity.org/cis-benchmarks/
Scroll through list for Checkpoint
Accepted internally by our security team as a valid approach.... maybe not definitive but good as a complement to any other sources.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The link target seems to have been removed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I updated the original post with a corrected link.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yeah, the SK team is wreaking havoc 🙂
