Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Joe_Kanaszka
Advisor

How to track/log GAIA portal access

Good morning - happy Friday!

How do you guys track/log access to the GAIA portal?  Do you need to use a separate syslog server, or can I configure access/edit events to go to my Check Point logging server?

How do you tighten up access to your GAIA portals?  Do you use 2FA?  If so, does anyone use DUO?

 

Thanks guys.

 

 

0 Kudos
3 Replies
the_rock
Legend
Legend

0 Kudos
(1)
Joe_Kanaszka
Advisor

Thanks Andy!  I'll take a look at that!.  Hey BTW - has a customer ever asked you to hide the Mobile Access portal so it does not show up at ALL in vuln scans?  I've disabled my SSL VPN by simply unchecking the options for it in "VPN Clients" and "Mobile Access". 

Now it is disabled, but a vuln scan still shows port 443 active.  If I go to the external IP of my security gateway, I see my old SSL VPN banner and an error "Access denied..  This portal is not supported on this server..."

I think I found an SK to configure your gateway to only allow "internal" connections to the portal:

sk105740

Have you ever used this approach to "hide" port 443 from the outside?

I'm doing this on my DR system first before my Prod system.  LOL

 

Thanks Andy!

 

 

 

 

0 Kudos
the_rock
Legend
Legend

Yes I have tried it and it did work.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events