Jumbo hotfix take does not match requirement-checkpoint-gaia
Vendor: checkpoint
OS: gaia
Description:
Indeni can verify that the take of the jumbo hotfix installed is a specific one.
Remediation Steps:
Install the correct jumbo hotfix take.
How does this work?
Using the Check Point command “installed_jumbo_take” we retreive the currently installed jumbo hotfixes.
Why is this important?
It is very important to make sure that devices are patched with the latest versions and hotfixes, to prevent downtime and security incidents.
Without Indeni how would you find this?
An administrator could login and manually run the command.
chkp-os-installed_jumbo_take
name: chkp-os-installed_jumbo_take
description: run "installed_jumbo_take"
type: monitoring
monitoring_interval: 60 minutes
requires:
vendor: checkpoint
os.name: gaia
asg:
neq: true
os.version.num:
compare-type: version-compare
op: "<"
value: "77.30"
comments:
hotfix-jumbo-take:
why: |
It is very important to make sure that devices are patched with the latest versions and hotfixes, to prevent downtime and security incidents.
how: |
Using the Check Point command "installed_jumbo_take" we retreive the currently installed jumbo hotfixes.
can-with-snmp: false
can-with-syslog: false
steps:
- run:
type: SSH
command: ${nice-path} -n 15 installed_jumbo_take -n; ${nice-path} -n 15 $CPDIR/bin/cpprod_util
CPPROD_GetValue "CPUpdates/6.0/BUNDLE_FIAT_HF_BASE_026" SU_Build_Take
0; ${nice-path} -n 15 $CPDIR/bin/cpprod_util CPPROD_GetValue "Check Point
Mini Suite/setup/FIAT_HF_BASE_026" Take 0; ${nice-path} -n 15 $CPDIR/bin/cpprod_util
CPPROD_GetValue "CPUpdates/6.0/BUNDLE_GIZMO_HF_041_050" SU_Build_Take
0; ${nice-path} -n 15 $CPDIR/bin/cpprod_util CPPROD_GetValue "Check Point
Mini Suite/setup/GIZMO_HF_041_050" Take 0; ${nice-path} -n 15 $CPDIR/bin/cpprod_util
CPPROD_GetValue "CPUpdates/6.0/BUNDLE_GULLI_HF_BASE_008" SU_Build_Take
0; ${nice-path} -n 15 $CPDIR/bin/cpprod_util CPPROD_GetValue "Check Point
Mini Suite/setup/GULLI_HF_BASE_008" Take 0; ${nice-path} -n 15 $CPDIR/bin/cpprod_util
CPPROD_GetValue "CPUpdates/6.0/BUNDLE_GYPSY_HF_BASE_021" SU_Build_Take
0; ${nice-path} -n 15 $CPDIR/bin/cpprod_util CPPROD_GetValue "Check Point
Mini Suite/setup/GYPSY_HF_BASE_021" Take 0; ${nice-path} -n 15 $CPDIR/bin/cpprod_util
CPPROD_GetValue "CPUpdates/6.0/BUNDLE_R77_20_JUMBO_HF" SU_Build_Take 0;
${nice-path} -n 15 $CPDIR/bin/cpprod_util CPPROD_GetValue "Check Point
Mini Suite/setup/R77_20_jumbo_hf" Take 0
parse:
type: AWK
file: installed_jumbo_take.parser.1.awk
crossvendor_compliance_check_hotfix_jumbo_take
Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/rules/templatebased/crossvendor/compliance/crossvendor_compliance_check_hotfix_jumbo_take.scala