<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint OPSEC log collection Error in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404774#M8402</link>
    <description>&lt;P&gt;So finally after so much troubleshooting i figured out the issue was with configurations on the Checkpoint device&lt;/P&gt;

&lt;P&gt;there are stanzas in the fwopsec.conf on Checkpoint at $FWDIR/conf/fwopsec.conf &lt;/P&gt;

&lt;P&gt;lea_server port 12345 --&amp;gt; when a port is assigned here opsec works on clear connections &lt;BR /&gt;
lea_server auth_port 23456 --&amp;gt; this is what accepts ssl connections (opsec sslca)&lt;/P&gt;

&lt;P&gt;So per my troubleshooting Splunk connects to Opsec only on SSL and wont work with CLEAR, therefore the &lt;STRONG&gt;lea_server auth_port 23456&lt;/STRONG&gt; stanza should exist in fwopsec.conf, Now when the auth_port is mentioned the type shall be mentioned in the &lt;STRONG&gt;fwopsec.conf&lt;/STRONG&gt; which is &lt;STRONG&gt;lea_server auth_type sslca&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;so for clear connections the fwopsec.conf should have &lt;BR /&gt;
&lt;STRONG&gt;lea_server port 12345&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;For sslca the fwopsec.conf should have stanzas&lt;BR /&gt;
&lt;STRONG&gt;lea_server auth_port 23456&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;lea_server auth_type sslca&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;If the port is &lt;STRONG&gt;0&lt;/STRONG&gt;(Zero) that means that type is disabled (Ex: &lt;STRONG&gt;lea_server auth_port 0&lt;/STRONG&gt; means sslca is disabled)&lt;/P&gt;

&lt;P&gt;Another thing, i guess Opsec can only listen either on clear or SSL but not both at same time, so make sure &lt;STRONG&gt;lea_server auth_port 23456&lt;/STRONG&gt; and &lt;STRONG&gt;lea_server auth_type sslca&lt;/STRONG&gt; exists in fwopsec.conf on checkpoint and it works like pro ;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 20:24:05 GMT</pubDate>
    <dc:creator>suryavicky21</dc:creator>
    <dc:date>2020-09-29T20:24:05Z</dc:date>
    <item>
      <title>Checkpoint OPSEC log collection Error</title>
      <link>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404768#M8396</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I am trying to integrate Checkpoint logs into Splunk using the OPSEC LEA modular input/TA. I notice the below error post configuring the connections and inputs&lt;/P&gt;

&lt;P&gt;2018-05-20 05:53:33,998 +0000 log_level=ERROR, pid=xxxx, tid=Thread-61667, file=ta_opseclea_data_collector.py, func_name=get_logs, code_line_no=75 | [input_name="name" connection="connecitonname" data="xxx"]log_level=0 file:lea_loggrabber.cpp func_name:check_session_end_reason code_line_no:1056 :ERROR: Session end reason: &lt;STRONG&gt;SIC ERROR 147 - SIC Error for lea: Authentication error&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I see this error for each of the inputs that is configured. &lt;BR /&gt;
the  setup is&lt;BR /&gt;
-- 1 Primary checkpoint Manager&lt;BR /&gt;
-- 1 Secondary checkpoint Manager&lt;BR /&gt;
-- 1 reporter manager server&lt;BR /&gt;
-- multiple gateways&lt;/P&gt;

&lt;P&gt;So i presume the certificate shall be pulled from the primary manager and the logs as well, as manager deals with all the gateways. I did pull the certificate from primary manager and configured the connections.conf for manager, but above is the error i see. Couldn't figure out yet the issue to fix. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Did anyone test the Checkpoint OPSEC LEA for splunk over distributed architecture that has a manager handling gateways and a reporter server.&lt;/P&gt;

&lt;P&gt;I would be glad if anyone can help me on this.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Surya Teja&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:35:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404768#M8396</guid>
      <dc:creator>suryavicky21</dc:creator>
      <dc:date>2020-09-29T19:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint OPSEC log collection Error</title>
      <link>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404769#M8397</link>
      <description>&lt;P&gt;Yes it’s been done in distributed environments pulling from the primary, etc as you described.&lt;/P&gt;

&lt;P&gt;A quick google of the error revealed several checkpoint articles that may apply:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk99130&amp;amp;t=1526823404788"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk99130&amp;amp;t=1526823404788&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120112&amp;amp;t=1526823447480"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120112&amp;amp;t=1526823447480&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Any of these help?&lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 13:39:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404769#M8397</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-05-20T13:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint OPSEC log collection Error</title>
      <link>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404770#M8398</link>
      <description>&lt;P&gt;tried these, but no luck. I did not find any error related to time though.&lt;BR /&gt;
I've installed the same on a single instance setup where there is only one manager handling multiple gateways, and the OPSEC LEA TA works like pro&lt;/P&gt;

&lt;P&gt;any more inputs please &lt;span class="lia-unicode-emoji" title=":neutral_face:"&gt;😐&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 06:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404770#M8398</guid>
      <dc:creator>suryavicky21</dc:creator>
      <dc:date>2018-05-21T06:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint OPSEC log collection Error</title>
      <link>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404771#M8399</link>
      <description>&lt;P&gt;I’d submit a ticket to splunk for support and escalate through your account rep if necessary.  At least you can have that working while more answers come in here... Best of luck!  &lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 15:23:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404771#M8399</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-05-21T15:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint OPSEC log collection Error</title>
      <link>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404772#M8400</link>
      <description>&lt;P&gt;If you're got an updated Linux server and you're running the latest add-on, there is a known error with glibc which fails to establish an OPSEC connected and download the certificate. Do you have a valid certificate?&lt;/P&gt;

&lt;P&gt;ls -la /opt/splunk/etc/apps/Splunk_TA_checkpoint-opseclea/certs&lt;/P&gt;

&lt;P&gt;Checkout the add-on release notes for more details.&lt;/P&gt;

&lt;P&gt;I worked around this by downgrading my glibc, setting up add-on, then upgrading glibc again.&lt;/P&gt;

&lt;P&gt;Best of luck.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:54:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404772#M8400</guid>
      <dc:creator>milesbrennan</dc:creator>
      <dc:date>2020-09-29T19:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint OPSEC log collection Error</title>
      <link>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404773#M8401</link>
      <description>&lt;P&gt;Thanks for the comment @milesbrennan&lt;BR /&gt;
there wasn't an issue pulling the cert. Add-on did fetch the cert, i've created the connection.conf and inputs.conf as well post which i see the SIC 147 error. Also i followed the procedure mentioned at Splunk docs to configure the inputs and cert&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 07:20:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404773#M8401</guid>
      <dc:creator>suryavicky21</dc:creator>
      <dc:date>2018-07-02T07:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint OPSEC log collection Error</title>
      <link>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404774#M8402</link>
      <description>&lt;P&gt;So finally after so much troubleshooting i figured out the issue was with configurations on the Checkpoint device&lt;/P&gt;

&lt;P&gt;there are stanzas in the fwopsec.conf on Checkpoint at $FWDIR/conf/fwopsec.conf &lt;/P&gt;

&lt;P&gt;lea_server port 12345 --&amp;gt; when a port is assigned here opsec works on clear connections &lt;BR /&gt;
lea_server auth_port 23456 --&amp;gt; this is what accepts ssl connections (opsec sslca)&lt;/P&gt;

&lt;P&gt;So per my troubleshooting Splunk connects to Opsec only on SSL and wont work with CLEAR, therefore the &lt;STRONG&gt;lea_server auth_port 23456&lt;/STRONG&gt; stanza should exist in fwopsec.conf, Now when the auth_port is mentioned the type shall be mentioned in the &lt;STRONG&gt;fwopsec.conf&lt;/STRONG&gt; which is &lt;STRONG&gt;lea_server auth_type sslca&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;so for clear connections the fwopsec.conf should have &lt;BR /&gt;
&lt;STRONG&gt;lea_server port 12345&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;For sslca the fwopsec.conf should have stanzas&lt;BR /&gt;
&lt;STRONG&gt;lea_server auth_port 23456&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;lea_server auth_type sslca&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;If the port is &lt;STRONG&gt;0&lt;/STRONG&gt;(Zero) that means that type is disabled (Ex: &lt;STRONG&gt;lea_server auth_port 0&lt;/STRONG&gt; means sslca is disabled)&lt;/P&gt;

&lt;P&gt;Another thing, i guess Opsec can only listen either on clear or SSL but not both at same time, so make sure &lt;STRONG&gt;lea_server auth_port 23456&lt;/STRONG&gt; and &lt;STRONG&gt;lea_server auth_type sslca&lt;/STRONG&gt; exists in fwopsec.conf on checkpoint and it works like pro ;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:24:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Checkpoint-OPSEC-log-collection-Error/m-p/404774#M8402</guid>
      <dc:creator>suryavicky21</dc:creator>
      <dc:date>2020-09-29T20:24:05Z</dc:date>
    </item>
  </channel>
</rss>

