Skip to content

Commit c19dba6

Browse files
authored
checkpoint: allow configuration of time zones (#5157)
1 parent 44a5c37 commit c19dba6

18 files changed

+216
-32
lines changed

packages/checkpoint/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "1.12.0"
3+
changes:
4+
- description: Allow configuration of time zones.
5+
type: enhancement
6+
link: https://github.com/elastic/integrations/pull/5157
27
- version: "1.11.0"
38
changes:
49
- description: Update package to ECS 8.6.0.

packages/checkpoint/data_stream/firewall/_dev/test/pipeline/test-checkpoint-with-time.log-expected.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,7 @@
2525
"original": "\u003c134\u003e1 2020-03-30T07:20:35Z gw-da58d3 CheckPoint 7776 - [action:\"Accept\"; flags:\"444676\"; ifdir:\"outbound\"; ifname:\"eth0\"; logid:\"0\"; loguid:\"{0x5e819dc3,0x0,0x353707c7,0xee78a1dc}\"; origin:\"192.168.1.100\"; originsicname:\"cn=cp_mgmt,o=gw-da58d3..tmn8s8\"; sequencenum:\"1\"; time:\"1594646954\"; version:\"5\"; __policy_id_tag:\"product=VPN-1 \u0026 FireWall-1[db_tag={880771B0-FD92-2C4F-82FC-B96FC3DE5A07};mgmt=gw-da58d3;date=1585502566;policy_name=Standard\\]\"; dst:\"192.168.1.153\"; inzone:\"Local\"; layer_name:\"Network\"; layer_uuid:\"63b7fe60-76d2-4287-bca5-21af87337b0a\"; match_id:\"1\"; parent_rule:\"0\"; rule_action:\"Accept\"; rule_uid:\"1fde807b-6300-4b1a-914f-f1c1f3e2e7d2\"; outzone:\"External\"; product:\"VPN-1 \u0026 FireWall-1\"; proto:\"17\"; s_port:\"43103\"; service:\"514\"; service_id:\"syslog\"; src:\"192.168.1.100\"]",
2626
"outcome": "success",
2727
"sequence": 1,
28+
"timezone": "UTC",
2829
"type": [
2930
"allowed",
3031
"connection"
@@ -101,7 +102,8 @@
101102
"id": "{0x60928f1d,0x8,0x40de101f,0xfcdbb197}",
102103
"kind": "event",
103104
"original": "\u003c134\u003e1 2021-05-05T12:27:09Z cp-m CheckPoint 1231 - [action:\"Drop\"; flags:\"278528\"; ifdir:\"inbound\"; ifname:\"bond1.3999\"; loguid:\"{0x60928f1d,0x8,0x40de101f,0xfcdbb197}\"; origin:\"127.0.0.1\"; originsicname:\"CN=CP,O=cp.com.9jjkfo\"; sequencenum:\"62\"; time:\"1620217629\"; version:\"5\"; __policy_id_tag:\"product=VPN-1 \u0026 FireWall-1[db_tag={F6212FB3-54CE-6344-9164-B224119E2B92};mgmt=cp-m;date=1620031791;policy_name=CP-Cluster]\"; action_reason:\"Dropped by multiportal infrastructure\"; dst:\"81.2.69.144\"; product:\"VPN \u0026 FireWall\"; proto:\"6\"; s_port:\"52780\"; service:\"80\"; src:\"81.2.69.144\"]",
104-
"sequence": 62
105+
"sequence": 62,
106+
"timezone": "UTC"
105107
},
106108
"network": {
107109
"direction": "inbound",
@@ -181,6 +183,7 @@
181183
"original": "\u003c134\u003e1 2022-12-02T16:39:12.000Z fwmgr CheckPoint 45470 - [action:\"Decrypt\"; flags:\"417028\"; ifdir:\"inbound\"; ifname:\"bond2.204\"; logid:\"0\"; loguid:\"{0xdca02360,0x9c491391,0xb5348f,0x1c07d10c}\"; origin:\"172.16.2.9\"; originsicname:\"CN=cp_mgmt,O=fwmgr.sdasdqdqd.com.ds2wd2\"; sequencenum:\"178\"; time:\"1669999152000\"; version:\"5\"; __policy_id_tag:\"product=VPN-1 \\u0026 FireWall-1[db_tag={F6212FB3-54CE-6344-9164-B224119E2B92};mgmt=fwmgr;date=1669986326;policy_name=Standard\\\\]\"; community:\"RemoteAccess\"; dst:\"192.168.1.153\"; fw_subproduct:\"VPN-1\"; inzone:\"External\"; lastupdatetime:\"1669999152\"; layer_name:\"Network\"; layer_uuid:\"e2117254-df10-4a5d-8d42-cacc362e077b\"; match_id:\"5\"; parent_rule:\"0\"; rule_action:\"Accept\"; rule_name:\"SysAdmn\"; rule_uid:\"9294591a-bc96-4916-bb63-926c31f8c943\"; methods::\"ESP: AES-128 + SHA1\"; outzone:\"Internal\"; peer_gateway:\"172.28.11.213\"; product:\"VPN-1 \\u0026 FireWall-1\"; proto:\"17\"; s_port:\"49129\"; scheme::\"IKE\"; service:\"53\"; service_id:\"domain-udp_\"; session_uid:\"{6389E8E3-0000-0000-AC10-0209F7730000}\"; src:\"192.168.1.153\"; src_user_dn:\" \"; src_user_name:\"srcuser \"; user:\"srcuser \"; vpn_feature_name:\"VPN\"]",
182184
"outcome": "success",
183185
"sequence": 178,
186+
"timezone": "UTC",
184187
"type": [
185188
"allowed",
186189
"connection"
@@ -262,6 +265,7 @@
262265
"original": "\u003c134\u003e1 2022-12-02T16:39:12.000Z fwmgr CheckPoint 45470 - [action:\"Decrypt\"; flags:\"417028\"; ifdir:\"inbound\"; ifname:\"bond2.204\"; logid:\"0\"; loguid:\"{0xdca02360,0x9c491391,0xb5348f,0x1c07d10c}\"; origin:\"172.16.2.9\"; originsicname:\"CN=cp_mgmt,O=fwmgr.sdasdqdqd.com.ds2wd2\"; sequencenum:\"178\"; time:\"2021-05-05T12:27:09Z\"; version:\"5\"; __policy_id_tag:\"product=VPN-1 \\u0026 FireWall-1[db_tag={F6212FB3-54CE-6344-9164-B224119E2B92};mgmt=fwmgr;date=1669986326;policy_name=Standard\\\\]\"; community:\"RemoteAccess\"; dst:\"192.168.1.153\"; fw_subproduct:\"VPN-1\"; inzone:\"External\"; lastupdatetime:\"1669999152\"; layer_name:\"Network\"; layer_uuid:\"e2117254-df10-4a5d-8d42-cacc362e077b\"; match_id:\"5\"; parent_rule:\"0\"; rule_action:\"Accept\"; rule_name:\"SysAdmn\"; rule_uid:\"9294591a-bc96-4916-bb63-926c31f8c943\"; methods::\"ESP: AES-128 + SHA1\"; outzone:\"Internal\"; peer_gateway:\"172.28.11.213\"; product:\"VPN-1 \\u0026 FireWall-1\"; proto:\"17\"; s_port:\"49129\"; scheme::\"IKE\"; service:\"53\"; service_id:\"domain-udp_\"; session_uid:\"{6389E8E3-0000-0000-AC10-0209F7730000}\"; src:\"192.168.1.153\"; src_user_dn:\" \"; src_user_name:\"srcuser \"; user:\"srcuser \"; vpn_feature_name:\"VPN\"]",
263266
"outcome": "success",
264267
"sequence": 178,
268+
"timezone": "UTC",
265269
"type": [
266270
"allowed",
267271
"connection"

packages/checkpoint/data_stream/firewall/_dev/test/pipeline/test-checkpoint.log

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,3 +19,4 @@
1919
<134>1 2020-03-30T07:19:22Z gw-da58d3 CheckPoint 8363 - [action:"Accept"; flags:"411908"; ifdir:"inbound"; ifname:"eth0"; logid:"0"; loguid:"{0x5e819d7a,0x0,0x353707c7,0xee78a1dc}"; origin:"192.168.1.100"; originsicname:"cn=cp_mgmt,o=gw-da58d3..tmn8s8"; sequencenum:"1"; version:"5"; __policy_id_tag:"product=VPN-1 & FireWall-1[db_tag={880771B0-FD92-2C4F-82FC-B96FC3DE5A07};mgmt=gw-da58d3;date=1585502566;policy_name=Standard\]"; dst:"192.168.1.255"; inzone:"External"; layer_name:"Network"; layer_uuid:"63b7fe60-76d2-4287-bca5-21af87337b0a"; match_id:"1"; parent_rule:"0"; rule_action:"Accept"; rule_uid:"1fde807b-6300-4b1a-914f-f1c1f3e2e7d2"; outzone:"Local"; product:"VPN-1 & FireWall-1"; proto:"17"; s_port:"50024"; service:"137"; service_id:"nbname"; src:"192.168.1.196"]
2020
<134>1 2020-03-30T07:20:33Z gw-da58d3 CheckPoint 8363 - [action:"Accept"; flags:"411908"; ifdir:"inbound"; ifname:"eth0"; logid:"0"; loguid:"{0x5e819dc1,0x0,0x353707c7,0xee78a1dc}"; origin:"192.168.1.100"; originsicname:"cn=cp_mgmt,o=gw-da58d3..tmn8s8"; sequencenum:"1"; version:"5"; __policy_id_tag:"product=VPN-1 & FireWall-1[db_tag={880771B0-FD92-2C4F-82FC-B96FC3DE5A07};mgmt=gw-da58d3;date=1585502566;policy_name=Standard\]"; dst:"192.168.1.100"; inzone:"External"; layer_name:"Network"; layer_uuid:"63b7fe60-76d2-4287-bca5-21af87337b0a"; match_id:"1"; parent_rule:"0"; rule_action:"Accept"; rule_uid:"1fde807b-6300-4b1a-914f-f1c1f3e2e7d2"; outzone:"Local"; product:"VPN-1 & FireWall-1"; proto:"6"; s_port:"60226"; service:"22"; service_id:"ssh"; src:"192.168.1.205"]
2121
<134>1 2020-03-30T07:20:35Z gw-da58d3 CheckPoint 8363 - [action:"Accept"; flags:"444676"; ifdir:"outbound"; ifname:"eth0"; logid:"0"; loguid:"{0x5e819dc3,0x0,0x353707c7,0xee78a1dc}"; origin:"192.168.1.100"; originsicname:"cn=cp_mgmt,o=gw-da58d3..tmn8s8"; sequencenum:"1"; version:"5"; __policy_id_tag:"product=VPN-1 & FireWall-1[db_tag={880771B0-FD92-2C4F-82FC-B96FC3DE5A07};mgmt=gw-da58d3;date=1585502566;policy_name=Standard\]"; dst:"192.168.1.153"; inzone:"Local"; layer_name:"Network"; layer_uuid:"63b7fe60-76d2-4287-bca5-21af87337b0a"; match_id:"1"; parent_rule:"0"; rule_action:"Accept"; rule_uid:"1fde807b-6300-4b1a-914f-f1c1f3e2e7d2"; outzone:"External"; product:"VPN-1 & FireWall-1"; proto:"17"; s_port:"43103"; service:"514"; service_id:"syslog"; src:"192.168.1.100"]
22+
<134>1 2020-03-30T07:20:35 gw-da58d3 CheckPoint 8363 - [action:"Accept"; flags:"444676"; ifdir:"outbound"; ifname:"eth0"; logid:"0"; loguid:"{0x5e819dc3,0x0,0x353707c7,0xee78a1dc}"; origin:"192.168.1.100"; originsicname:"cn=cp_mgmt,o=gw-da58d3..tmn8s8"; sequencenum:"1"; version:"5"; __policy_id_tag:"product=VPN-1 & FireWall-1[db_tag={880771B0-FD92-2C4F-82FC-B96FC3DE5A07};mgmt=gw-da58d3;date=1585502566;policy_name=Standard\]"; dst:"192.168.1.153"; inzone:"Local"; layer_name:"Network"; layer_uuid:"63b7fe60-76d2-4287-bca5-21af87337b0a"; match_id:"1"; parent_rule:"0"; rule_action:"Accept"; rule_uid:"1fde807b-6300-4b1a-914f-f1c1f3e2e7d2"; outzone:"External"; product:"VPN-1 & FireWall-1"; proto:"17"; s_port:"43103"; service:"514"; service_id:"syslog"; src:"192.168.1.100"]

0 commit comments

Comments
 (0)