- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi Team,
We are trying to integrate Forcscout with the checkpoint.
Gaia OS R80.20 with jumbo take_103
Communication happens in between Checkpoint MGMT and Forescout.
From Forescout able to telnet with 18184 port to Checkpoint MGMT.
Refer the below screenshot for details
Still, face the below error:-
Pls, help to resolve the issue.
Regards,
Hi Team,
We resolved the issue.
Reason: Time and date are not up to date😉
We also disable the smart event blade because by default smartevent also works on the same port 18184.
Also make sure that the OPSEC object name on checkpoint and the object name define on the third-party ForceScout name should same.
Additional Information:- You need to download and add the add-ons (Checkpoint Threat Prevention) on ForeScout to able to see the detection and Remediate information on ForeScout and also ForeScout required an additional license.
For Reference :
1
2
3
Thanks and Regards
Hi Team,
We resolved the issue.
Reason: Time and date are not up to date😉
We also disable the smart event blade because by default smartevent also works on the same port 18184.
Also make sure that the OPSEC object name on checkpoint and the object name define on the third-party ForceScout name should same.
Additional Information:- You need to download and add the add-ons (Checkpoint Threat Prevention) on ForeScout to able to see the detection and Remediate information on ForeScout and also ForeScout required an additional license.
For Reference :
1
2
3
Thanks and Regards
Hi,
Did you run log and management in the same server? We are able to establish SIC but we are not receiving events.
HIi @Hamid_Nabil
Yes, we have only one Management Server for policy configuration and also store the logs.
Also, refer the below links.
Regards
Hi,
I also integrated CheckPoint (R80.30 take 111) with Forescout. All events from Gateway works fine and are recognize with CounterACT but it ignore logs form Endpoints (SandBlast Agents).
I can't find any information what kind of blades/products ForeScout understand. Does anybody know is it should feed IOCs from endpoint also?
Rafal
@Rafal_N Is your ForeScout checkpoint plugin integrated with log server or management? I ask this because my management server is receiving indexed logs from log server. I could not establish SIC between ForeScout and log-server but it was established with management server. And still no event being was sent to ForeScout. 😞
With management all logs form Endpoint and form Gateway are send to management.
All other events like Antibot or Anti-Virus or TE that are generated by Gateway are visible on ForeScout. Only problem is with logs from Endpoint Client.
Hi @Rafal_N
In Forescout we able to see Checkpoint Anti-Bot Threat Detections, Checkpoint Anti-Virus Threat Detections, Checkpoint Threat Emulation Threat Detection is only for CP Firewall which also required additional adds on.
For Checkpoint Endpoint Client you need to create a custom policy in ForeScout.
Refer below link for more details.
Regards
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY