CIS Check Point Firewall Benchmark

Secure configuration guidelines for Check Point Security Gateway and Management

v1.1.0 November 2024

Overview

▶

This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Check Point Security Gateways and Management Servers. Recommendations cover system configuration, authentication, security policy, VPN, logging and monitoring, and high availability.

~100Recommendations
6Sections
2Profile Levels
SectionAreaFocus
1System ConfigOS hardening, management
2AuthenticationAdmins, password policy
3Security PolicyRules, threat prevention
4VPNSite-to-site, remote access
5LoggingLog server, monitoring
6HA/MaintenanceClusterXL, backups

Profile Definitions

▶
ProfileDescriptionIntended Use
L1Level 1 — StandardEssential security for all Check Point Firewall deployments; minimal performance impact.
L2Level 2 — HardenedAdvanced hardening for PCI-DSS, HIPAA, or high-security environments.

1 — System Configuration

▶

1.1 OS Hardening

▶
1.1.1 Ensure Gaia OS Is Running Latest Supported Version (Manual)
L1 Manual
Description

This recommendation verifies that Gaia OS Is Running Latest Supported Version on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Gaia OS Is Running Latest Supported Version. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Gaia OS Is Running Latest Supported Version. Install policy to apply the changes.

1.1.2 Ensure Secure Internal Communication Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Secure Internal Communication Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Secure Internal Communication Is Enabled. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Secure Internal Communication Is Enabled. Install policy to apply the changes.

1.1.3 Ensure Unused Network Interfaces Are Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Unused Network Interfaces Are Disabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Unused Network Interfaces Are Disabled. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Unused Network Interfaces Are Disabled. Install policy to apply the changes.

1.1.4 Ensure NTP Is Configured with Authenticated Sources (Automated)
L1 Auto
Description

This recommendation verifies that NTP Is Configured with Authenticated Sources on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that NTP Is Configured with Authenticated Sources. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure NTP Is Configured with Authenticated Sources. Install policy to apply the changes.

1.2 Management Access

▶
1.2.1 Ensure HTTPS Is Used for Management Access (Automated)
L1 Auto
Description

This recommendation verifies that HTTPS Is Used for Management Access on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that HTTPS Is Used for Management Access. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure HTTPS Is Used for Management Access. Install policy to apply the changes.

1.2.2 Ensure SSH Uses Strong Ciphers and Key Exchange (Automated)
L1 Auto
Description

This recommendation verifies that SSH Uses Strong Ciphers and Key Exchange on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that SSH Uses Strong Ciphers and Key Exchange. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure SSH Uses Strong Ciphers and Key Exchange. Install policy to apply the changes.

1.2.3 Ensure Management Interface Is Restricted to Specific IPs (Automated)
L1 Auto
Description

This setting ensures that Management Interface Is Restricted to Specific IPs on the Check Point Firewall security gateway. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Check Point Firewall security gateway is essential for defense in depth.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Management Interface Is Restricted to Specific IPs. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Management Interface Is Restricted to Specific IPs. Install policy to apply the changes.

1.2.4 Ensure Console Timeout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Console Timeout Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Console Timeout Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Console Timeout Is Configured. Install policy to apply the changes.

2 — Authentication & Users

▶

2.1 Admin Authentication

▶
2.1.1 Ensure Default Admin Password Is Changed (Manual)
L1 Manual
Description

This recommendation verifies that Default Admin Password Is Changed on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Default Admin Password Is Changed. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Default Admin Password Is Changed. Install policy to apply the changes.

2.1.2 Ensure Multi-Factor Authentication Is Enabled for Admins (Automated)
L1 Auto
Description

This recommendation verifies that Multi-Factor Authentication Is Enabled for Admins on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Multi-Factor Authentication Is Enabled for Admins. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Multi-Factor Authentication Is Enabled for Admins. Install policy to apply the changes.

2.1.3 Ensure Role-Based Admin Access Is Configured (Manual)
L1 Manual
Description

This recommendation verifies that Role-Based Admin Access Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Role-Based Admin Access Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Role-Based Admin Access Is Configured. Install policy to apply the changes.

2.1.4 Ensure Admin Session Timeout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Admin Session Timeout Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Admin Session Timeout Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Admin Session Timeout Is Configured. Install policy to apply the changes.

2.2 Password Policy

▶
2.2.1 Ensure Password Complexity Is Enforced (Automated)
L1 Auto
Description

This recommendation ensures that Password Complexity Is Enforced on the Check Point Firewall security gateway. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Check Point Firewall security gateway may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Password Complexity Is Enforced. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Password Complexity Is Enforced. Install policy to apply the changes.

2.2.2 Ensure Password Expiration Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Password Expiration Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Password Expiration Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Password Expiration Is Configured. Install policy to apply the changes.

2.2.3 Ensure Account Lockout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Account Lockout Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Account Lockout Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Account Lockout Is Configured. Install policy to apply the changes.

2.2.4 Ensure RADIUS or TACACS+ Integration Is Configured (Automated)
L2 Auto
Description

This recommendation verifies that RADIUS or TACACS+ Integration Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that RADIUS or TACACS+ Integration Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure RADIUS or TACACS+ Integration Is Configured. Install policy to apply the changes.

3 — Security Policy

▶

3.1 Firewall Rules

▶
3.1.1 Ensure Default Policy Is Drop All (Automated)
L1 Auto
Description

This recommendation verifies that Default Policy Is Drop All on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Default Policy Is Drop All. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Default Policy Is Drop All. Install policy to apply the changes.

3.1.2 Ensure Stealth Rule Hides Gateway Interfaces (Automated)
L1 Auto
Description

This recommendation verifies that Stealth Rule Hides Gateway Interfaces on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Stealth Rule Hides Gateway Interfaces. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Stealth Rule Hides Gateway Interfaces. Install policy to apply the changes.

3.1.3 Ensure Cleanup Rule Logs Dropped Traffic (Automated)
L1 Auto
Description

This recommendation verifies that Cleanup Rule Logs Dropped Traffic on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Cleanup Rule Logs Dropped Traffic. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Cleanup Rule Logs Dropped Traffic. Install policy to apply the changes.

3.1.4 Ensure Rules Are Ordered by Specificity (Manual)
L1 Manual
Description

This recommendation verifies that Rules Are Ordered by Specificity on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Rules Are Ordered by Specificity. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Rules Are Ordered by Specificity. Install policy to apply the changes.

3.1.5 Ensure Unused Rules Are Disabled or Removed (Manual)
L1 Manual
Description

This recommendation verifies that Unused Rules Are Disabled or Removed on the Check Point Firewall security gateway. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Check Point Firewall security gateway increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Unused Rules Are Disabled or Removed. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Unused Rules Are Disabled or Removed. Install policy to apply the changes.

3.2 Threat Prevention

▶
3.2.1 Ensure IPS Blade Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that IPS Blade Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that IPS Blade Is Enabled. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure IPS Blade Is Enabled. Install policy to apply the changes.

3.2.2 Ensure Anti-Bot Blade Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Anti-Bot Blade Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Anti-Bot Blade Is Enabled. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Anti-Bot Blade Is Enabled. Install policy to apply the changes.

3.2.3 Ensure Threat Emulation Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that Threat Emulation Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Threat Emulation Is Enabled. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Threat Emulation Is Enabled. Install policy to apply the changes.

3.2.4 Ensure Threat Extraction Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that Threat Extraction Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Threat Extraction Is Enabled. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Threat Extraction Is Enabled. Install policy to apply the changes.

4 — VPN Configuration

▶

4.1 Site-to-Site VPN

▶
4.1.1 Ensure VPN Community Uses AES-256 Encryption (Automated)
L1 Auto
Description

This recommendation verifies that VPN Community Uses AES-256 Encryption on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that VPN Community Uses AES-256 Encryption. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure VPN Community Uses AES-256 Encryption. Install policy to apply the changes.

4.1.2 Ensure Perfect Forward Secrecy Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Perfect Forward Secrecy Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Perfect Forward Secrecy Is Enabled. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Perfect Forward Secrecy Is Enabled. Install policy to apply the changes.

4.1.3 Ensure IKEv2 Is Used (Automated)
L1 Auto
Description

This recommendation verifies that IKEv2 Is Used on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that IKEv2 Is Used. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure IKEv2 Is Used. Install policy to apply the changes.

4.1.4 Ensure VPN Tunnel Monitoring Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that VPN Tunnel Monitoring Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that VPN Tunnel Monitoring Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure VPN Tunnel Monitoring Is Configured. Install policy to apply the changes.

4.2 Remote Access VPN

▶
4.2.1 Ensure Remote Access VPN Uses Strong Authentication (Automated)
L1 Auto
Description

This recommendation verifies that Remote Access VPN Uses Strong Authentication on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Remote Access VPN Uses Strong Authentication. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Remote Access VPN Uses Strong Authentication. Install policy to apply the changes.

4.2.2 Ensure SSL VPN Portal Is Properly Secured (Automated)
L1 Auto
Description

This recommendation verifies that SSL VPN Portal Is Properly Secured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that SSL VPN Portal Is Properly Secured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure SSL VPN Portal Is Properly Secured. Install policy to apply the changes.

4.2.3 Ensure Endpoint Compliance Check Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that Endpoint Compliance Check Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Endpoint Compliance Check Is Enabled. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Endpoint Compliance Check Is Enabled. Install policy to apply the changes.

5 — Logging & Monitoring

▶

5.1 Log Configuration

▶
5.1.1 Ensure Logging Is Enabled for All Security Policies (Automated)
L1 Auto
Description

This recommendation verifies that Logging Is Enabled for All Security Policies on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Logging Is Enabled for All Security Policies. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Logging Is Enabled for All Security Policies. Install policy to apply the changes.

5.1.2 Ensure Log Server Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Log Server Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Log Server Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Log Server Is Configured. Install policy to apply the changes.

5.1.3 Ensure Log Rotation Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Log Rotation Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Log Rotation Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Log Rotation Is Configured. Install policy to apply the changes.

5.1.4 Ensure Encrypted Log Transfer Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that Encrypted Log Transfer Is Enabled on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Encrypted Log Transfer Is Enabled. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Encrypted Log Transfer Is Enabled. Install policy to apply the changes.

5.2 Monitoring

▶
5.2.1 Ensure SmartEvent Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that SmartEvent Is Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that SmartEvent Is Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure SmartEvent Is Configured. Install policy to apply the changes.

5.2.2 Ensure SNMP Is Configured with SNMPv3 (Automated)
L2 Auto
Description

This recommendation verifies that SNMP Is Configured with SNMPv3 on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that SNMP Is Configured with SNMPv3. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure SNMP Is Configured with SNMPv3. Install policy to apply the changes.

5.2.3 Ensure CPU and Memory Alerts Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that CPU and Memory Alerts Are Configured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that CPU and Memory Alerts Are Configured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure CPU and Memory Alerts Are Configured. Install policy to apply the changes.

6 — High Availability & Maintenance

▶

6.1 High Availability

▶
6.1.1 Ensure ClusterXL Is Configured for HA (Automated)
L1 Auto
Description

This recommendation verifies that ClusterXL Is Configured for HA on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that ClusterXL Is Configured for HA. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure ClusterXL Is Configured for HA. Install policy to apply the changes.

6.1.2 Ensure Failover Is Tested and Documented (Manual)
L1 Manual
Description

This recommendation verifies that Failover Is Tested and Documented on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Failover Is Tested and Documented. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Failover Is Tested and Documented. Install policy to apply the changes.

6.1.3 Ensure Sync Network Is Dedicated and Secured (Automated)
L1 Auto
Description

This recommendation verifies that Sync Network Is Dedicated and Secured on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Sync Network Is Dedicated and Secured. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Sync Network Is Dedicated and Secured. Install policy to apply the changes.

6.2 Maintenance

▶
6.2.1 Ensure Hotfix Accumulator Is Current (Manual)
L1 Manual
Description

This recommendation verifies that Hotfix Accumulator Is Current on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Hotfix Accumulator Is Current. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Hotfix Accumulator Is Current. Install policy to apply the changes.

6.2.2 Ensure Backup Is Configured and Tested (Automated)
L1 Auto
Description

This recommendation verifies that Backup Is Configured and Tested on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Backup Is Configured and Tested. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Backup Is Configured and Tested. Install policy to apply the changes.

6.2.3 Ensure Snapshot Is Taken Before Changes (Manual)
L1 Manual
Description

This recommendation verifies that Snapshot Is Taken Before Changes on the Check Point Firewall security gateway. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Check Point Firewall security gateway vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

In SmartConsole, navigate to the appropriate configuration page and verify that Snapshot Is Taken Before Changes. Alternatively, use clish or cpstat from the CLI.

Remediation

In SmartConsole, navigate to the appropriate settings and configure Snapshot Is Taken Before Changes. Install policy to apply the changes.