- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
I have a Checkpoint Log Server that is the center point of logs for 6 firewalls. I've setup a LEA connection to that server from a SOC log collection appliance, TCP 18186, which works fine, and another one to a QRadar SIEM 18185 which doesn't work at all. I've restarted services and rebooted, the LogServer just wont listen on the port. I've confirmed this with netstat. Attached is the fwopsec file from the Checkpoint logs server. Any help is appreciated.
Thanks,
Justin
My question is: why do you need to use multiple LEA ports?
Particularly when they are both unauthenticated?
The only place I've seen two different LEA ports used is when one of them is authenticated, the other is not.
Something like in this SK: Configuring a Log Server R76 and lower to work with both SmartEvent component and an OPSEC LEA serve...
I don't believe you can do two unauthenticated LEA ports.
https://community.checkpoint.com/people/bbent09791668-5ef8-377b-845e-545aff695211?
My question is: why do you need to use multiple LEA ports?
Particularly when they are both unauthenticated?
The only place I've seen two different LEA ports used is when one of them is authenticated, the other is not.
Something like in this SK: Configuring a Log Server R76 and lower to work with both SmartEvent component and an OPSEC LEA serve...
I don't believe you can do two unauthenticated LEA ports.
https://community.checkpoint.com/people/bbent09791668-5ef8-377b-845e-545aff695211?
Thanks for the reply Dameon. I didn't realize that I could point two log sources at the same LEA instance. When you say "unauthenticated", I mean, they do exchange certificates and SIC information. Would you say they are still unauthenticated in that instance ?
Thanks again,
Justin
I mean unauthenticated.
This is based on what it says in sk89620 and the screenshot of your fwopsec.conf says.
You probably want to change the line to auth_port instead of just port if you want SIC authentication
Note that LEA has been multi-threaded (and able to support multiple endpoints connecting) since R77.
What Dameon said 🙂 Would just add that if both do SIC, then there's no need for the fwopsec.conf edits. Use the defaults and have them connect on the same port 18184. Will simplify things when you do an upgrade.
Thanks for the many responses. Couldn't get it to work on 18184. I did a tcpdump and currently traffic between log and management server exist on that port. I got it work with 18186 but most of the pertinent fields come across as *** Confidential *** . I'm assuming perhaps checkpoint doesn't like to send this info across the wire in the clear ?
Going to try 18184 again.
Second try worked with 18184, going to change my other log source as well. Thanks for all the help. I haven't worked on Checkpoints for 10+ years back when they were on Nokias so I am more than a little rusty.
This guide was helpful on the QRADAR side.
Great to hear
I still have a few Nokia boxes at my house from back in the days when I worked there.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
22 | |
14 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY