Configuring a FW-1 firewall
Previous  Top  Next


This information is from a post on the LogAnalysis forum.

http://lists.jammed.com/loganalysis/2001/09/0006.html

This applies to the UNIX version of Firewall-1.

You can use the Checkpoint command $FWDIR/bin/fw log -f to convert from the Checkpoint proprietary log format to plain text, and then the UNIX "logger" utility to get the plain text into syslog. However, be aware that the "fw log -f" converts *everything* in the network connections log to text -- so every time you stop and restart the firewall, you will blat out everything in the connections log back into syslog. We recommend to our customers that they perform a log rotation on the network connection logs every time they restart the system - that way there are no duplicates.

Also, there's a lot of valuable information about the health of the firewall that doesn't show up in either the network connection logs or the standard host OS syslog, especially if you use the GUI for firewall management (this includes things like administrators logging into and out of the GUI, and pushing new policies to the firewalls). If you want to capture that info in your central log server, you need to do the "logger" trick described above with the file $FWDIR/log/cpmgmt.aud.