156-215.80 · Question #314
On R80.10 when configuring Third-Party devices to read the logs using the LEA (Log Export API) the default Log Server uses port:
The correct answer is B. 18184. The Check Point LEA (Log Export API) uses TCP port 18184 by default for third-party devices to read logs from the Log Server.
Question
On R80.10 when configuring Third-Party devices to read the logs using the LEA (Log Export API) the default Log Server uses port:
Options
- A18210
- B18184
- C257
- D18191
How the community answered
(30 responses)- B93% (28)
- C3% (1)
- D3% (1)
Why each option
The Check Point LEA (Log Export API) uses TCP port 18184 by default for third-party devices to read logs from the Log Server.
Port 18210 is associated with Check Point SmartLog and the Solr indexing service, not the LEA protocol.
Port 18184 is the default TCP port assigned to the Check Point LEA service, which allows third-party SIEM and logging applications to pull log records from the Check Point Log Server using the OPSEC LEA protocol. This port must be open between the third-party device and the Log Server for log export to function.
Port 257 is the FW1_log port used for log forwarding between the Security Gateway and the Management/Log Server, not for third-party LEA client access.
Port 18191 is used by Check Point for SmartUpdate and policy installation communications, not for LEA log export.
Concept tested: Check Point LEA default port for third-party log access
Source: https://support.checkpoint.com/results/sk/sk56763
Topics
Community Discussion
No community discussion yet for this question.