CIS Check Point Firewall Benchmark
Secure configuration guidelines for Check Point Security Gateway and Management
v1.1.0 November 2024Overview
▶This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Check Point Security Gateways and Management Servers. Recommendations cover system configuration, authentication, security policy, VPN, logging and monitoring, and high availability.
| Section | Area | Focus |
|---|---|---|
| 1 | System Config | OS hardening, management |
| 2 | Authentication | Admins, password policy |
| 3 | Security Policy | Rules, threat prevention |
| 4 | VPN | Site-to-site, remote access |
| 5 | Logging | Log server, monitoring |
| 6 | HA/Maintenance | ClusterXL, backups |
Profile Definitions
▶| Profile | Description | Intended Use |
|---|---|---|
| L1 | Level 1 — Standard | Essential security for all Check Point Firewall deployments; minimal performance impact. |
| L2 | Level 2 — Hardened | Advanced hardening for PCI-DSS, HIPAA, or high-security environments. |
1 — System Configuration
▶1.1 OS Hardening
▶This recommendation verifies that Gaia OS Is Running Latest Supported Version on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Gaia OS Is Running Latest Supported Version. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Gaia OS Is Running Latest Supported Version. Install policy to apply the changes.
This recommendation verifies that Secure Internal Communication Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Secure Internal Communication Is Enabled. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Secure Internal Communication Is Enabled. Install policy to apply the changes.
This recommendation verifies that Unused Network Interfaces Are Disabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Unused Network Interfaces Are Disabled. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Unused Network Interfaces Are Disabled. Install policy to apply the changes.
This recommendation verifies that NTP Is Configured with Authenticated Sources on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that NTP Is Configured with Authenticated Sources. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure NTP Is Configured with Authenticated Sources. Install policy to apply the changes.
1.2 Management Access
▶This recommendation verifies that HTTPS Is Used for Management Access on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that HTTPS Is Used for Management Access. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure HTTPS Is Used for Management Access. Install policy to apply the changes.
This recommendation verifies that SSH Uses Strong Ciphers and Key Exchange on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that SSH Uses Strong Ciphers and Key Exchange. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure SSH Uses Strong Ciphers and Key Exchange. Install policy to apply the changes.
This setting ensures that Management Interface Is Restricted to Specific IPs on the Check Point Firewall security gateway. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Check Point Firewall security gateway is essential for defense in depth.
In SmartConsole, navigate to the appropriate configuration page and verify that Management Interface Is Restricted to Specific IPs. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Management Interface Is Restricted to Specific IPs. Install policy to apply the changes.
This recommendation verifies that Console Timeout Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Console Timeout Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Console Timeout Is Configured. Install policy to apply the changes.
2 — Authentication & Users
▶2.1 Admin Authentication
▶This recommendation verifies that Default Admin Password Is Changed on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Default Admin Password Is Changed. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Default Admin Password Is Changed. Install policy to apply the changes.
This recommendation verifies that Multi-Factor Authentication Is Enabled for Admins on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Multi-Factor Authentication Is Enabled for Admins. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Multi-Factor Authentication Is Enabled for Admins. Install policy to apply the changes.
This recommendation verifies that Role-Based Admin Access Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Role-Based Admin Access Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Role-Based Admin Access Is Configured. Install policy to apply the changes.
This recommendation verifies that Admin Session Timeout Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Admin Session Timeout Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Admin Session Timeout Is Configured. Install policy to apply the changes.
2.2 Password Policy
▶This recommendation ensures that Password Complexity Is Enforced on the Check Point Firewall security gateway. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Check Point Firewall security gateway may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
In SmartConsole, navigate to the appropriate configuration page and verify that Password Complexity Is Enforced. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Password Complexity Is Enforced. Install policy to apply the changes.
This recommendation verifies that Password Expiration Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Password Expiration Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Password Expiration Is Configured. Install policy to apply the changes.
This recommendation verifies that Account Lockout Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Account Lockout Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Account Lockout Is Configured. Install policy to apply the changes.
This recommendation verifies that RADIUS or TACACS+ Integration Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that RADIUS or TACACS+ Integration Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure RADIUS or TACACS+ Integration Is Configured. Install policy to apply the changes.
3 — Security Policy
▶3.1 Firewall Rules
▶This recommendation verifies that Default Policy Is Drop All on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Default Policy Is Drop All. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Default Policy Is Drop All. Install policy to apply the changes.
This recommendation verifies that Stealth Rule Hides Gateway Interfaces on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Stealth Rule Hides Gateway Interfaces. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Stealth Rule Hides Gateway Interfaces. Install policy to apply the changes.
This recommendation verifies that Cleanup Rule Logs Dropped Traffic on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Cleanup Rule Logs Dropped Traffic. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Cleanup Rule Logs Dropped Traffic. Install policy to apply the changes.
This recommendation verifies that Rules Are Ordered by Specificity on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Rules Are Ordered by Specificity. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Rules Are Ordered by Specificity. Install policy to apply the changes.
This recommendation verifies that Unused Rules Are Disabled or Removed on the Check Point Firewall security gateway. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Check Point Firewall security gateway increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
In SmartConsole, navigate to the appropriate configuration page and verify that Unused Rules Are Disabled or Removed. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Unused Rules Are Disabled or Removed. Install policy to apply the changes.
3.2 Threat Prevention
▶This recommendation verifies that IPS Blade Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that IPS Blade Is Enabled. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure IPS Blade Is Enabled. Install policy to apply the changes.
This recommendation verifies that Anti-Bot Blade Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Anti-Bot Blade Is Enabled. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Anti-Bot Blade Is Enabled. Install policy to apply the changes.
This recommendation verifies that Threat Emulation Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Threat Emulation Is Enabled. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Threat Emulation Is Enabled. Install policy to apply the changes.
This recommendation verifies that Threat Extraction Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Threat Extraction Is Enabled. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Threat Extraction Is Enabled. Install policy to apply the changes.
4 — VPN Configuration
▶4.1 Site-to-Site VPN
▶This recommendation verifies that VPN Community Uses AES-256 Encryption on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that VPN Community Uses AES-256 Encryption. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure VPN Community Uses AES-256 Encryption. Install policy to apply the changes.
This recommendation verifies that Perfect Forward Secrecy Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Perfect Forward Secrecy Is Enabled. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Perfect Forward Secrecy Is Enabled. Install policy to apply the changes.
This recommendation verifies that IKEv2 Is Used on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that IKEv2 Is Used. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure IKEv2 Is Used. Install policy to apply the changes.
This recommendation verifies that VPN Tunnel Monitoring Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that VPN Tunnel Monitoring Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure VPN Tunnel Monitoring Is Configured. Install policy to apply the changes.
4.2 Remote Access VPN
▶This recommendation verifies that Remote Access VPN Uses Strong Authentication on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Remote Access VPN Uses Strong Authentication. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Remote Access VPN Uses Strong Authentication. Install policy to apply the changes.
This recommendation verifies that SSL VPN Portal Is Properly Secured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that SSL VPN Portal Is Properly Secured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure SSL VPN Portal Is Properly Secured. Install policy to apply the changes.
This recommendation verifies that Endpoint Compliance Check Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Endpoint Compliance Check Is Enabled. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Endpoint Compliance Check Is Enabled. Install policy to apply the changes.
5 — Logging & Monitoring
▶5.1 Log Configuration
▶This recommendation verifies that Logging Is Enabled for All Security Policies on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Logging Is Enabled for All Security Policies. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Logging Is Enabled for All Security Policies. Install policy to apply the changes.
This recommendation verifies that Log Server Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Log Server Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Log Server Is Configured. Install policy to apply the changes.
This recommendation verifies that Log Rotation Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Log Rotation Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Log Rotation Is Configured. Install policy to apply the changes.
This recommendation verifies that Encrypted Log Transfer Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Encrypted Log Transfer Is Enabled. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Encrypted Log Transfer Is Enabled. Install policy to apply the changes.
5.2 Monitoring
▶This recommendation verifies that SmartEvent Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that SmartEvent Is Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure SmartEvent Is Configured. Install policy to apply the changes.
This recommendation verifies that SNMP Is Configured with SNMPv3 on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that SNMP Is Configured with SNMPv3. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure SNMP Is Configured with SNMPv3. Install policy to apply the changes.
This recommendation verifies that CPU and Memory Alerts Are Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that CPU and Memory Alerts Are Configured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure CPU and Memory Alerts Are Configured. Install policy to apply the changes.
6 — High Availability & Maintenance
▶6.1 High Availability
▶This recommendation verifies that ClusterXL Is Configured for HA on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that ClusterXL Is Configured for HA. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure ClusterXL Is Configured for HA. Install policy to apply the changes.
This recommendation verifies that Failover Is Tested and Documented on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Failover Is Tested and Documented. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Failover Is Tested and Documented. Install policy to apply the changes.
This recommendation verifies that Sync Network Is Dedicated and Secured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Sync Network Is Dedicated and Secured. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Sync Network Is Dedicated and Secured. Install policy to apply the changes.
6.2 Maintenance
▶This recommendation verifies that Hotfix Accumulator Is Current on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Hotfix Accumulator Is Current. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Hotfix Accumulator Is Current. Install policy to apply the changes.
This recommendation verifies that Backup Is Configured and Tested on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Backup Is Configured and Tested. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Backup Is Configured and Tested. Install policy to apply the changes.
This recommendation verifies that Snapshot Is Taken Before Changes on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
In SmartConsole, navigate to the appropriate configuration page and verify that Snapshot Is Taken Before Changes. Alternatively, use clish or cpstat from the CLI.
In SmartConsole, navigate to the appropriate settings and configure Snapshot Is Taken Before Changes. Install policy to apply the changes.