SecureXL configuration mismatch across cluster members-checkpoint-all

SecureXL configuration mismatch across cluster members-checkpoint-all
0

SecureXL configuration mismatch across cluster members-checkpoint-all

Vendor: checkpoint

OS: all

Description:
indeni will identify when two devices are part of a cluster and alert if the SecureXL settings are different for different VS’s.

Remediation Steps:
Compare the output of “fwaccel stat” across members of the cluster, make sure to run the command in the correct vsenv context.

chkp-fw-accel-stat-vsx

name: chkp-fw-accel-stat-vsx
description: Get securexl status information
type: monitoring
monitoring_interval: 5 minutes
requires:
    vendor: checkpoint
    role-firewall: 'true'
    vsx: 'true'
comments:
    securexl-status:
        skip-documentation: true
    securexl-disabled-from-rule:
        skip-documentation: true
steps:
-   run:
        type: SSH
        file: fwaccel-stat-vsx.remote.1.bash
    parse:
        type: AWK
        file: fwaccel-stat-vsx.parser.1.awk

checkpoint_compare_securexl_setting_vsx

// Deprecation warning : Scala template-based rules are deprecated. Please use YAML format rules instead.

package com.indeni.server.rules.library.templatebased.checkpoint

import com.indeni.server.rules.RuleContext
import com.indeni.server.rules.library.templates.SnapshotComparisonTemplateRule
/**
  *
  */
case class checkpoint_compare_securexl_setting_vsx() extends SnapshotComparisonTemplateRule(
  ruleName = "checkpoint_compare_securexl_setting_vsx",
  ruleFriendlyName = "Check Point Cluster (VSX): SecureXL configuration mismatch across cluster members",
  ruleDescription = "indeni will identify when two devices are part of a cluster and alert if the SecureXL settings are different for different VS's.",
  metricName = "securexl-status",
  applicableMetricTag = "vs.id",
  isArray = false,
  alertDescription = "The members of a cluster of Check Point firewalls must have the same SecureXL settings.\n\nThis alert was added per the request of <a target=\"_blank\" href=\"http://il.linkedin.com/pub/gal-vitenberg/83/484/103\">Gal Vitenberg</a>.",
  baseRemediationText = """Compare the output of "fwaccel stat" across members of the cluster, make sure to run the command in the correct vsenv context.""")()