3.20 Ensure Logging is enabled for Track Options of Global Properties

Information

This defines the system-wide logging and alerting of parameters.

Rationale:

This enables the logging and alerting for specific types of parameters.

VPN successful key exchange: specifies the action to be taken when VPN keys are successfully exchanged.

VPN packet handling errors: specifies the action to be taken when encryption or decryption errors occur. A log entry contains the action performed (Drop or Reject) and a short description of the error cause, for example, scheme or method mismatch.

VPN configuration & key exchange errors: specifies the action to be taken when logging configuration or key exchange errors occur, for example, when attempting to establish encrypted communication with a network object inside the same encryption domain.

IP Options drop: specifies the action to take when a packet with IP Options is encountered. The Check Point Security Gateway always drops these packets, but you can log them or issue an alert.

Administrative notifications: specifies the action to be taken when an administrative event (for example, when a certificate is about to expire) occurs.

SLA violation: specifies the action to be taken when an SLA violation occurs, as defined in the Virtual Links window.

Connection matched by SAM: specifies the action to be taken when a connection is blocked by SAM (Suspicious Activities Monitoring).

Dynamic object resolution failure: specifies the action to be taken when a dynamic object cannot be resolved.

Log every authenticated HTTP connection: specifies that a log entry should be generated for every authenticated HTTP connection.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Logging is set to Log or Popup Alert or Mail Alert or SNMP Trap Alert for the following events

SmartConsole > Global Properties > Log and Alert > Track Options
VPN successful key exchange
VPN packet handling errors
VPN configuration & key exchange errors
IP Options drop
Administrative Notification
Connection matched by SAM
Dynamic object resolution failure
Packet is incorrectly tagged
Packet tagging brute force attack

Checked the Log every authenticated HTTP connection.

See Also

https://workbench.cisecurity.org/files/2828

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: CheckPoint

Control ID: 0aec69fe30ed6713a33dc5b9cd79e1a91351dee58f4cc2f72ccc7d9ed4a2cf80