Check Point Firewall R80.x - Training Lab 10 | Adding dedicated log server with some troubleshooting

  Рет қаралды 8,907

Magnus Holmberg

Magnus Holmberg

Күн бұрын

Пікірлер: 46
@DeepakKumar-ov8ko
@DeepakKumar-ov8ko 4 жыл бұрын
Your understanding of topic is excellent ! I am surprised to see less number of subscribers ,Keep continue your good work .
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 жыл бұрын
Thank you! We have actually increased by over 200 subs the last month so hopefully it increase over the next months :) I think its fun to make the videos so i dont mind, but always fun if more ppl watch it. I found it really hard to find good check point content on youtube so tought i could contribute with some content :D
@bonelessss
@bonelessss 2 жыл бұрын
Hi Magnus, I'm a total newbie involved in a total migration from R76 to 80.40 and, honestly, your videos saved my life. Can thank you enough for the great job and superb explanation, will only say that in one of our calls to CP they've provided one of your videos as example of what should we do to solve an issue we had. Can't believe the low number of subscribers, you just keep with the good work and hopefully more people will appreciate this job well done. Greetings from Spain!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 жыл бұрын
Thank you! It’s really fun to see that the videos are helpful :) Haha that’s pretty cool, I haven’t heard that before. Am aware that there are a few ppl at check point watching them :) I guess check point owe me a few beers at the next CPX event :D
@bonelessss
@bonelessss 2 жыл бұрын
@@MagnusHolmberg-NetSec don't know about CP but I do own you a couple of beers. Let me know if you visit Madrid someday and will gladly pay my debt 😊
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 жыл бұрын
@@bonelessss hehe no worries! If you see me in an event just say hi :)
@JayGpt
@JayGpt 2 жыл бұрын
you the best, bonus part is awesome only someone with vast experience will know.
@ricardoinfante5001
@ricardoinfante5001 2 жыл бұрын
I love when you have error in the config, because show how resolving.... very nice !! Thanks
@thabosthabos7397
@thabosthabos7397 Жыл бұрын
This is great and well documented. Thank you for the knowledge.
@tomato524308
@tomato524308 4 жыл бұрын
Helped to relate with my production network. Thanks for this content!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 жыл бұрын
Thank you for watching and am glad it helped :) enjoy the rest of the serie.
@SUNNY-gg1vd
@SUNNY-gg1vd 4 жыл бұрын
Most of your content belongs to Production Environment senario which is very hard to find on KZbin........keep making this kind of videos 👍
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 жыл бұрын
Thank you :) Yes I personally think that the CCSA certificate skips out many vital things and they are not even within CCSE. Within a larger organization you will learn it after working with the products after some months or a year. But within a small environment it’s hard to get recommendation, blueprints etc, So this “CCSA” course includes what I think is expected from a certified tech working or wanting to work with check point :) Regarding you tube content, it’s generally hard to find something :( hopefully we can add some more. The ppl at my work is asking for content regarding MDS and VSX :)
@syedshohidahmed9880
@syedshohidahmed9880 4 жыл бұрын
Hi Magnus, I only just found your channel as I searching for VSX. I would like to thank you for your time and effort in creating these videos, they have been very helpful. Please don't remove the troubleshooting parts they are very helpful. Looking forward to seeing the complete VSX and MDS videos, and also could you do some videos on Bonds and Ethernet sub interfaces
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 жыл бұрын
Welcome to the channel! Yes when it comes to the MDS / VSX i will for sure have it included as its a large part of managing a larger environment. within this specific playlist (the ccsa) i try to keep it pretty streamline, well some hickups are needed to actually learn :) But i try to avoid things that goes more on a CCSE level. I will not be able to build bonds etc in the lab, but i will take screenshots and some short clips from real production VSX installations with bonds so its possible to actually see bonds/vlan/multiq etc. Thank you for watching and i do hope you learn something :)
@anandkarnekar477
@anandkarnekar477 3 жыл бұрын
Very helpfull video, It help me to understand logs setup and how to setup dedicated server in my envirement
@AR-ic6jf
@AR-ic6jf 4 жыл бұрын
Excellent work 👍
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 жыл бұрын
Thank you, hope you enjoy the rest of the content for this course :D
@desaironak11
@desaironak11 4 жыл бұрын
excellent explanation.
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 жыл бұрын
Thank you :)
@mohankumar49
@mohankumar49 3 жыл бұрын
Hi Magnus, Can you help us with the video how to import the older logs to the management and view those logs in smart log dashboard. This would be helpful
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 жыл бұрын
Aha thats a good suggestion on a video actually. Its more and more common as if you need to go back in the logs for a security incident they will ask for longs a longtime back aswell. I will see if i can prepp a video for that.
@jaimaheshwari6548
@jaimaheshwari6548 2 жыл бұрын
Thanks Magnus and it is really helpful
@ch1ttybang543
@ch1ttybang543 3 жыл бұрын
@magnus thank you so much for providing these videos. I was wondering if you have a PDF or PowerPoint you wouldn't mind providing when following these logs. Thanks in advance!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 жыл бұрын
Your welcome, I don’t really have any pdf / PowerPoint. But there are instructions within the installation and upgrade guide sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_Installation_and_Upgrade_Guide/206107
@ghsi007
@ghsi007 3 жыл бұрын
'install database' what is it for? And what would happen if we dont perform this step?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 жыл бұрын
Am not sure of the full process for the install database and what actually happens in the background. But in general when doing changes within mgmt objects on the mgmt server i always do the install database. So in regards to a logserver, if its not done the logs can display incorrect objects for example. All of this serie is based on real world and my experience, if doing like this it do work :) Honestly i havn´t digged to much in to why you need to do specific things. So i will qoute Timothy_Hall on one of his forum posts. ‎ " 2018-09-24 02:39 PM I get this question all the time in the CCSA classes I teach, and the best way I've found to explain it is the following: "Install Database" is more or less a subset of an "Install Policy" operation to a security gateway. Prior to starting the verification and compilation of a gateway's security policy, the SMS (and any other secondary SMS's or separate Log Servers) needs to "get its own house in order" by checking for any configuration changes on the SMS object or other Global Property settings that affect its own operation. This could be any change on the SMS object itself such as enabling the Compliance blade, the SmartEvent blade, a change in firewall log retention policy, and/or any changes made to locally-defined user accounts in the SmartDashboard/SmartConsole as mentioned above. If there are any changes detected the SMS implements them in its own live configuration before proceeding. In R77.30 the "Install Database" operation invoked the command "fwm dbload" on the SMS which performed some or perhaps all of the "Install Database" operation, but I'm not sure if this command is still relevant in R80.10. Note that a publish operation in R80+ management simply commits proposed/candidate changes in an administrator's session to the SMS's postgres database configuration, and is a completely different type of operation. " Also see the documentation :) sc1.checkpoint.com/documents/R80/CP_R80_SmartDashboard_OLH/html_frameset.htm?topic=documents/R80/CP_R80_SmartDashboard_OLH/1XsAOD74nmuI7gyc1V59rg2
@ithead522
@ithead522 4 жыл бұрын
Hi, Can we have the log server separated from the production and install on a VMWARE box in the production? Do we need to have additional license to do so? Please advice. Thank you.
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 жыл бұрын
Hi, yes logserver can be separated from the mgmt server. Yes a logserver licens is needed Regards Magnus
@luisfcaetano
@luisfcaetano 3 жыл бұрын
I have a problem when I a add new partition disk with 2TB or more, my logs are very slow sometimes I can't see any log. What is the best practice to have more than 2TB for log server ? and the best configuration hardware, like 16GPU, 32GB RAM ?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 жыл бұрын
2TB during what timeframe? I think sizing of boxes are counted logs/seconds. For our log servers we use 8 CPU and 64GB ram, but it really depends on the environment. We have customers that split there logs out on 3 log servers due to the amount of user logs from web filtering from 100K users.
@luisfcaetano
@luisfcaetano 3 жыл бұрын
@@MagnusHolmberg-NetSec 2TB I can save only one month, sometimes 15 days.
@luisfcaetano
@luisfcaetano 3 жыл бұрын
@@MagnusHolmberg-NetSec Can I have other disk with 2TB and make a LVM to add in /var/log? having 4tb ?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 жыл бұрын
@@luisfcaetano sure you add more disc after and extend the volume It’s the next video in this playlist ;) kzbin.info/www/bejne/h3uphoSrg9ipgNU I do gzip everything that is older then 15 days and ship it to a different box. If gzip the logs they take about 10% of the space (you can not search for them if gzip) so this is just to be able to save more logs then the 15days or so. It will require CPU to gzip and transfer logs. Do you see that the CPU load is working hard? (More or less check so there is not a process or something that just stuck and eating all the performance) we have something similar about 1-1.5TB per 15days in our MLM (multi domain logserver) What version are you running?
@luisfcaetano
@luisfcaetano 3 жыл бұрын
​ @Magnus Holmberg I running on R80.40 take 119. Sometimes on day I create a file with old logs (tar.gz) , but I don't have a script to do this automate. I'll create one. I have another question about Smart Event, I need a specific license to use like CPSM-LOGS? When I activated the blade SmartEvent I received a alert about that I don't have a license. And one more question, Do you have a SIEM ? or Syslog like grafana or ELK ?
@yashpalsingh8649
@yashpalsingh8649 3 жыл бұрын
Great Explanation
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 жыл бұрын
thank you :)
@parmarvn
@parmarvn 4 жыл бұрын
Complete VSX , End to end Study and Configuration and Troubleshooting on VSX
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 жыл бұрын
MDS / VSX serie is in the process, first 2 videos is out and next one is coming in few days. :) kzbin.info/aero/PL4Jm1LJEII4ZIFjiPJKzwEIGJxfFBF9XQ
@awesome-clips2023
@awesome-clips2023 3 жыл бұрын
thank you!!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 жыл бұрын
No worries!
@desaironak11
@desaironak11 4 жыл бұрын
VPN Video next please
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 4 жыл бұрын
hehe ye i will fix the VPN video this month, just have been very busy,.
@desaironak11
@desaironak11 4 жыл бұрын
@@MagnusHolmberg-NetSec No Problem Sir :-)
Check Point Firewall R80.x - Training Lab 11 |  Compliance blade
27:25
Magnus Holmberg
Рет қаралды 3,4 М.
Check Point | Backups
26:24
Magnus Holmberg
Рет қаралды 8 М.
БАБУШКА ШАРИТ #shorts
0:16
Паша Осадчий
Рет қаралды 4,1 МЛН
Vampire SUCKS Human Energy 🧛🏻‍♂️🪫 (ft. @StevenHe )
0:34
Alan Chikin Chow
Рет қаралды 138 МЛН
Ful Video ☝🏻☝🏻☝🏻
1:01
Arkeolog
Рет қаралды 14 МЛН
Check Point | 3rd Party Site to Site VPN
26:58
Magnus Holmberg
Рет қаралды 20 М.
How To's Deploy Checkpoint Log Server
8:00
Silesio Carvalho
Рет қаралды 3,4 М.
Check Point VSX - Training Lab 1 | VSX Cluster Install
31:45
Magnus Holmberg
Рет қаралды 14 М.
Understanding fw monitor utility
27:13
Check Point Training Bytes
Рет қаралды 10 М.
Check Point Firewall - fw monitor
15:22
Magnus Holmberg
Рет қаралды 16 М.
Best of CheckMates: My Top Check Point CLI Commands
28:57
Check Point Software
Рет қаралды 9 М.
Check Point Firewall R80.40 - Training Lab 2 | Management HFA upgrade
20:00
gw cluster R80.10 upgrade to R81.10
18:21
Yaniv Atia
Рет қаралды 7 М.
БАБУШКА ШАРИТ #shorts
0:16
Паша Осадчий
Рет қаралды 4,1 МЛН