Checkpoint FW1 Log Levels

Hi people,

I hope someone can give me a brief overview - I have a client asking what level they should set their logging to on their Checkpoint FW1 device. Now I haven't been able to get in contact with them to obtain any further information at the moment and also haven't been able to find anything about Checkpoint FW1 log-levels on the net so far.

Is anyone able to give me a very brief overview of the logging levels available on FW1, or point me in the direction of something that will explain what the client is needing resolved?

From what I have found, my feeling at the moment is that FW1 just logs everything as a syslog type log file and that the log collector is able to capture based on I guess the severity of the log, ie, warning only, debugging, etc.

Any input at all would be greatly appreciated. Or if it sounds like I'm barking up the wrong tree altogether and you know a little bit about FW1, please feel free to correct my understanding.

Thanks in advance.

Matt

Reply to
Matt A
Loading thread data ...

Hi Matt,

imho - i find that your question is scenario based. For forensics purposes how often do you need to do tracking / auditting? How much detail do you require (informational? Debugging?) What sort of company is the CPFW protecting? Bank / Medical / Goverment ?

It's best to err on the side of caution - but also bear in mind that some DOS / DDOS attacks could overwhlem the FW, writing logs to disk until the disk is full - effectivily DOS your own FW.

In my experinces, it has always been best _not_ to log broadcast traffic (dhcp, nbt, broadcasts, stp etc) - generally speaking i create a rule above the "drop all" rule with these broadcast protocols and implicitily disable logging. The drop all rule has logging enable - for forensics and troubleshooting pruposes.

Cheers dirk

Reply to
jag456

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.