CheckPoint Firewall
CheckPoint Firewall enables you to fetch and analyze logs from Check Point Firewall devices.
Enhancement
Description | Issue ID | Reference ID |
---|---|---|
Added Syslog Collector based Check Point log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template. | KB-23294 | - |
Past Releases
CheckPoint Firewall v5.1.2
Release Date: February 7, 2023
Supported On: Logpoint 5.2.0 or later
Download: CheckPoint_Firewall_5.1.2.pak
SHA256: 2a379b9394ec2c83cfb64bc22fad1c5c437314058d0119fb0e2d00afe9e0fbf3
Enhancements
Description | Issue ID | Reference ID | |
---|---|---|---|
Renamed the following label: |
KB-10601 | - | |
Former Label | Updated Label | ||
User, LogOut | User, LogOut, Logoff | ||
Improved the normalization performance of CheckPointOpsecCompiledNormalizer. |
KB-18389 | 69431 | |
Updated the signature by adding a relevant field in the LP_Checkpoint Firewall to normalize CheckPointFirewallnew log format. |
KB-12411 | 49853 | |
Created a new compiled normalizerCheckPointFirewallCEFCompiledNormalizer, which supports the CheckPoint Firewall logs. | KB-17217 | ||
Added new signatures in LP_CheckPoint Firewall to normalize CheckPoint Firewall logs. In addition, the following labels are renamed: |
KB-16697 | 61745 | |
Former Taxonomy | Updated Taxonomy | ||
nat_add_rule | nat_add_rule_number | ||
browser | client_type | ||
user_dn | source_user_dn | ||
dst_user_dn |
destination_user_dn | ||
uid | log_uid | ||
user_id | uid | ||
peer_address | peer_gateway | ||
algorithm | encryption_method |
Bug Fix
The following issue is fixed:
Description | Issue ID | Reference ID |
Some CheckPoint logs were not normalized by CheckpointFirewallCEFCompiledNormalizer and CheckPointInfinityCompiledNormalizer. |
KB-14267, KB-17361, KB-17737, KB-16124 | 59844, 67105, 67137, 64210 |
CheckPoint Firewall v5.0.2
Enhancement
-
The following unused parsers have been removed from CheckPoint Firewall:
-
Syslog Parser
- Line Parser
-
Stacktrace Parser
-
- The CheckPointInfinityCompiledNormalizer now supports logs from Check Point Log Exporter.
- CheckPoint Firewall now adds a new label Logoff for the logout action.
CheckPoint Firewall v5.0.1
Enhancement
A minor update has been done in the CheckPoint Firewall's normalizer for better signature handling.
CheckPoint Firewall v3.6.0
Release Date: February 05, 2021
Supported On: Logpoint 6.0.0 to 6.6.6
Download: CheckPoint_Firewall_3.6.0.pak
SHA256:434ab97d95eb84e778b422723211715e0259c1c9fdf4e623a65784da005e02f7
Enhancement
A minor update has been done in the CheckPoint Firewall's normalizer for better signature handling.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.