Check Point Quantum Firewall
You must have the "Firewall" integrations license pack to use this feature.
You can integrate Check Point Quantum Firewall with Sophos Central so that it sends audit data to Sophos for analysis.
This integration uses a log collector hosted on a virtual machine (VM). Together they are called a data collector. The data collector receives third-party data and sends it to the Sophos Data Lake.
You can add multiple Quantum Firewalls to the same Sophos data collector.
To do this, set up your Quantum Firewall integration in Sophos Central, then configure one firewall to send logs to it. Then configure your other Quantum firewalls to send logs to the same Sophos data collector.
You don't have to repeat the Sophos Central part of the setup.
The key steps to add an integration are as follows:
- Add an integration for this product. This configures an image to use on a VM.
- Download and deploy the image on your VM. This becomes your data collector.
- Configure Quantum Firewall to send data to the data collector.
Data collectors have system and network access requirements. To check that you meet them, see Data collector requirements.
Add an integration
To integrate Quantum Firewall with Sophos Central, do as follows:
- In Sophos Central, go to Threat Analysis Center and click Integrations.
Click Check Point Quantum Firewall.
If you've already set up connections to Quantum Firewall, you see them here.
If this is the first integration you've added, we'll ask for details about your internal domains and IPs. See My domains and IPs.
Configure the VM
In Integration setup steps you configure a VM to receive data from Quantum Firewall. You can use an existing VM, or create a new one.
To configure the VM, do as follows:
- Add a name and description for the new integration.
Enter a name and description for the data collector.
If you've already set up a data collector integration you can choose it from a list.
Select the virtual platform. Currently we support VMware ESXi 6.7 or later and Microsoft Hyper-V 6.0.6001.18016 (Windows Server 2016) or later.
Specify the IP settings for the Internet-facing network ports. This sets up the management interface for the VM.
Select DHCP to assign the IP address automatically.
If you select DHCP, you must reserve the IP address.
Select Manual to specify network settings.
Select the Syslog IP version and enter the Syslog IP address.
You'll need this syslog IP address later, when you configure Quantum Firewall to send data to your data collector.
Select a Protocol.
You must use the same protocol when you configure Quantum Firewall to send data to your data collector.
We create the integration and it appears in your list.
In the integration details, you can see the port number for the data collector. You'll need this later when you configure Quantum Firewall to send data to it.
It might take a few minutes for the VM image to be ready.
Deploy the VM
If you're using ESXi, the OVA file is verified with Sophos Central, so it can only be used once. If you have to deploy another VM, you must create an OVA file again in Sophos Central.
Use the VM image to deploy the VM. To do this, do as follows:
- In the list of integrations, in Actions, click the download action for your platform, for example Download OVA for ESXi.
- When the image download finishes, deploy it on your VM. See Deploy a VM for integrations.
When you've deployed the VM, the integration shows as Connected.
Configure Quantum Firewall
Now go to Quantum Firewall and configure the Check Point Log Exporter to send audit data to us.
You can do this using the command line interface (CLI), or the SmartConsole.
To configure Log Exporter using CLI commands, use the
cp_log_export command on the log server.
The syntax is as follows:
cp_log_export add name <name> [domain-server <domain-server>] target-server <target-server IP/host name> target-port <target-port> protocol <(udp|tcp)> format <(cef)|(syslog)> [optional arguments]
Before you run the command, configure it with the following information:
In MDS or MLM mode the domain-server argument is required. Configure it as follows:
mdsas the value for
domain-serverto export MDS level audit logs.
allas the value for
domain-serverto configure the integration on every domain.
domain-serverIP address or name configures the integration on a specific domain.
Target-servercan use the IP address or DNS name.
This creates a new target directory with the unique name specified in
Set the following
target-serverparameters to the connection details for your Sophos data collector:
- IP Address
You must enter the same IP address, port and protocol settings you entered in Sophos Central when you added the integration.
We recommend you set
- To start the new log exporter with the new parameters run
cp_log_export restart. It doesn't start automatically.
For more details on the cp_log_export command, see Log Exporter - Basic Deployment.
Your Quantum Firewall data should appear in the Sophos Data Lake after validation.
To configure Log Exporter using SmartConsole, see the Check Point Logging and Monitoring Administration Guide. See Logging and Monitoring Administration Guide.