4-49
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 4 Configuring Firewall Devices
Check Point Devices
Step 1
Under Firewall & Log Server Settings, select the check box next to the desired log server, and click
Log
Info
.
Step 2
Select
Self
.
Step 3
Specify values for the following fields:
•
Reporting IP
— Enter the IP address of the interface in the log server from which MARS will pull
security event logs. This address represents either a virtual IP address associated with a CLM, an
MLM, or another log server. To learn more about the reporting IP address, its role, and
dependencies, see
Understanding Access IP, Reporting IP, and Interface Settings, page 2-8
.
•
Logging Access Type
— This value identifies the authentication method to use for LEA traffic,
which is the protocol used to pull security logs from the log server. Select
ASYMSSLC
,
CLEAR
,
or
SSLCA
, For more information on the access type and port, see
Select the Access Type for LEA
and CPMI Traffic, page 4-32
.
•
Logging Port
— Verify that the port number in the corresponds to the value specified in the
LEA_SERVER auth_port line of the
fwopsec.conf
file on this log server. The default
authentication method for configuration discovery is SSLCA and data is passed on port 18184.
Step 4
If this log server uses SSLCA or ASYMSSLCA as an authentication method, specify values for the
following fields (Otherwise, the authentication method is CLEAR. Skip to
Step 5
):
•
Certificate
— Either select the previously defined server from the list or click
Add
to define a new
certificate authority and continue with
Add a Check Point Certificate Server, page 4-47
.
•
Client SIC Name
— Enter the SIC DN of the OPSEC application for the MARS Appliance. This
value was obtained in
Define an OPSEC Application that Represents MARS, page 4-27
.
•
Server SIC Name
— Enter the SIC DN for the child enforcement module. This value was obtained
in
Obtain the Server Entity SIC Name, page 4-30
. Typically, this value is the SIC DN of the
SmartCenter server or of the CMA. In the case of Provider-1 and SiteManager-1 NGX (R60), this
value is the SIC DN of the MDS that manages the CMA.
Step 5
Click
Submit
to save your changes to this log server.
Step 6
Repeat
Step 1
through
Step 5
for each discovered log server.