Infrastructure Automation with Indeni 7.6

Notice: This blog post was originally published on Indeni before its acquisition by BlueCat.

The content reflects the expertise and perspectives of the Indeni team at the time of writing. While some references may be outdated, the insights remain valuable. For the latest updates and solutions, explore the rest of our blog

Check Point Device Hardening 

Device hardening is a necessary step to ensure your security devices do not have any potential loopholes which can be exploited by hackers. In 7.6.1, we added new Auto-Detect Elements (ADE) to harden Check Point firewalls. These checks apply to Check Point GAiA devices as well as Maestro devices. 

  1. Check for Strong passwords 
    • Ensure minimum password length is set to a user defined length.  
    • Ensure the password contains a combination of uppercase and lowercase letters, numbers and special characters.
  1. Ensure password complexity is set to 3. 
  1. Close inactive SSH sessions automatically. Ensure a timeout for automatic disconnection for inactive sessions is set. The wait time is >0 and <10 minutes by default. The timeout value is user configurable. 
  1. Ensure “Login Banner” is set to prohibit unauthorized access.
  1. Ensure remote management is using SSH v2 and not SSH v1. 
  1. Ensure that the local admin user accounts will not be blocked by checking that the CLI accounts are not being blocked under any circumstances.  

SecureXL Disabled Enhancements

Prior to 7.6, Indeni only collected the global status of SecureXL and alerted based on enable/disable status. In 7.6, Indeni will alert if SecureXL is disabled by the firewall as a result of certain conditions. 

Three new ADE’s were added to collect the state of the three SecureXL templates used to accelerate the connections: Accept, Drop and NAT. Indeni will alert if any one of these templates is disabled. 

These templates are available in version R80.10 later. The new rules are only applicable to Check Point GAiA devices.

Other New Auto-Detect Elements

  1. Check Point Light Out Management (LOM)
    • New ADE to collect the TLS version, IP address and Firmware information. Indeni will alert if the LOM interface was configured with default values. 
  1. Extended the support of the “configuration mismatch” rule to Palo Alto Networks devices. 

Next Steps

To see a complete list of features and bug fixes, refer to the release notes page on our website. You can download the latest list of Auto-Detect Elements for Maestro here. As always, if you have questions or comments, we’re here to help. 


Published in:


An avatar of the author

Ulrica de Fort-Menares is the Vice President of Product Management for Infrastructure Assurance.

Related content

Three operational reasons to drop legacy tools and unify your DDI

Three operational reasons to drop legacy tools and unify your DDI

Learn with BlueCat how visibility and control, process automation, and infrastructure reliability offer three reasons to adopt Unified DDI.

Read more
Micetro_ Simplify Microsoft DNS_ DHCP_ and Active Directory Sites Management

Simplify Microsoft DNS, DHCP, and Active Directory with Micetro

Learn how Micetro makes it easy to administer Microsoft DNS, DHCP, and Active Directory sites and subnets and manage your DDI environment.

Read more
Get insight into your DDI environment with Live DDI Analytics

Get insight into your DDI environment with Live DDI Analytics

Enroll in our technology preview today to use the Live DDI Analytics tool to get real-time reports and analysis for your DDI environment.

Read more
Three business-focused reasons to embrace Unified DDI

Three business-focused reasons to embrace Unified DDI

Discover with BlueCat how cost optimization, risk reduction, and accelerated digital transformation offer three reasons to adopt Unified DDI.

Read more

Legacy DDI approaches can pose challenges like system fragmentation, security gaps, and manual processes that result in network outages. Join our webinar on April 23 to learn how a unified DDI solution will address these challenges and transform your network.