nerdexam
Check_Point

156-215.80 · Question #314

On R80.10 when configuring Third-Party devices to read the logs using the LEA (Log Export API) the default Log Server uses port:

The correct answer is B. 18184. The Check Point LEA (Log Export API) uses TCP port 18184 by default for third-party devices to read logs from the Log Server.

Monitoring and Reporting

Question

On R80.10 when configuring Third-Party devices to read the logs using the LEA (Log Export API) the default Log Server uses port:

Options

  • A18210
  • B18184
  • C257
  • D18191

How the community answered

(30 responses)
  • B
    93% (28)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The Check Point LEA (Log Export API) uses TCP port 18184 by default for third-party devices to read logs from the Log Server.

A18210

Port 18210 is associated with Check Point SmartLog and the Solr indexing service, not the LEA protocol.

B18184Correct

Port 18184 is the default TCP port assigned to the Check Point LEA service, which allows third-party SIEM and logging applications to pull log records from the Check Point Log Server using the OPSEC LEA protocol. This port must be open between the third-party device and the Log Server for log export to function.

C257

Port 257 is the FW1_log port used for log forwarding between the Security Gateway and the Management/Log Server, not for third-party LEA client access.

D18191

Port 18191 is used by Check Point for SmartUpdate and policy installation communications, not for LEA log export.

Concept tested: Check Point LEA default port for third-party log access

Source: https://support.checkpoint.com/results/sk/sk56763

Topics

#LEA#Log Export API#port number#third-party integration

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice