<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are IPS Staging Protections? And how do we clear them? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2727#M102318</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://community.checkpoint.com/migrated-users/6703"&gt;Tomer Sole&lt;/A&gt; Sole and &lt;A href="https://community.checkpoint.com/migrated-users/54886"&gt;Raz Shlomo&lt;/A&gt; for expanding on explanation for the protections behavior.&lt;/P&gt;&lt;P&gt;The problem that I have with this, is that there&amp;nbsp;is not a single protection left with "Detect" in the "Optimized" and "Basic" after above mention update irrespective of the confidence level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "Low Confidence" was selected for simplicity and because in the profile definition, it is explicitly states that "Low Confidence" should be in "Detect" mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand their absence from "Detect(Staging)", but after first update, the only modes displayed are "Disabled" and "Protect".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC was able to verify my findings and are reaching out to R&amp;amp;D for information about this behavior.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Jun 2018 16:51:50 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2018-06-19T16:51:50Z</dc:date>
    <item>
      <title>What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2717#M102308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In R80, following an IPS Update, newly downloaded protections are marked in "staging". This means that if their state according to the profile is Prevent or Detect, as long as the user doesn't clear the flag, it's marked as "Detect (staging)" with a little clock icon on top of it. Protections that should be inactive remain inactive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The plan is that you can keep them in staging until you decide whether they should behave according the profile's settings, or override them with a different action, for example based on traffic after policy installation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the IPS Protections view, you can filter protections to only show the ones that are in Staging.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="staging.png" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/54285_staging.png" style="width: 620px; height: 281px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can control this setting from the Profile Editor:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="profile-staging.png" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/54286_profile-staging.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Clearing protections from Staging&lt;/STRONG&gt; can be done from the IPS Protections view.&lt;/P&gt;&lt;P&gt;Please note that in order to change the staging counter, you have to clear a protection from staging in &lt;STRONG&gt;all IPS profiles, not just the ones that are seen on the screen.&lt;/STRONG&gt; So either change the visible profiles to “all”:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="show-all-profiles.png" class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/54290_show-all-profiles.png" style="width: 620px; height: 101px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or make sure you clear the staging status from all profiles by right-clicking the protection and selecting “restore to profile settings”.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="restore-to-profile-settings.png" class="image-4 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/54291_restore-to-profile-settings.png" style="width: 620px; height: 491px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2016 08:10:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2717#M102308</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2016-09-13T08:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2718#M102309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears the Clear staging option is grayed out and cannot be selected.&amp;nbsp; How do I clear the staging without doing the restore to profile option?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Apr 2017 20:47:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2718#M102309</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2017-04-18T20:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2719#M102310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I apologize for not seeing this sooner.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure what you mean, clearing the staging de facto restores the activation to the profile's setting... Is there something else that you wish to do there?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jun 2017 09:37:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2719#M102310</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2017-06-06T09:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2720#M102311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tomer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not see&amp;nbsp;any protections in "Detect" or&amp;nbsp;"Staging" status on any protections in the profile cloned from "Optimized", after updates are downloaded :&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-6 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66466_pastedImage_6.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66461_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66462_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even with "Additional Activation" enabled, I still expect to see the low confidence in "Detect" if not&amp;nbsp;"Staging"&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66463_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But there are none in those states present. When filtered by "Low Confidence", all protections are disabled.&lt;/P&gt;&lt;P&gt;I am also not seeing filters for "Activation Status" even when it is selected:&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66464_pastedImage_4.png" /&gt;&amp;nbsp;&lt;IMG class="image-5 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66465_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 00:04:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2720#M102311</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-06-18T00:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2721#M102312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the profile being used by the policy? Or is it hidden from the view since it's not in use?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/66468_1 only used.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/66469_2 change it.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 04:01:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2721#M102312</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-06-18T04:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2722#M102313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the active profile used in the Policy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66486_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66487_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 12:25:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2722#M102313</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-06-18T12:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2723#M102314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this shouldn't happen.... please open a support ticket&amp;nbsp;so that we will have an R&amp;amp;D team looking at the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 16:55:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2723#M102314</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-06-18T16:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2724#M102315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Opened&amp;nbsp;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;A href="https://usercenter.checkpoint.com:443/usercenter/portal?action=UCPreLogin&amp;amp;srDetails=true&amp;amp;serviceRequestId=3-0371393181"&gt;3-0371393181.&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;If you could help facilitating its resolution, I'll be much obliged.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;So far, no dice. To make things even more interesting, I've just pulled the IPS update on my second Management server in a separate infrastructure and am looking at identical situation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Unless I am exceptionally lucky, I suspect that something is changed in the way updates are behaving.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;To summarize:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;1. When multiple profiles, including three stock profiles are filtered to show a "low confidence" protections, only "Strict" has them in "Detect" or "Staging" modes:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-8" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66517_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;2. There are no traces in the Audit Log that would indicate any changes to the behavior of the protections prior to the update that borked them:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;IMG __jive_id="66509" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66509_pastedImage_1.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;The stock profiles were untouched and the only profile that was subjected to any kind of manipulation was the clone of the "Optimized with TE and TX removed:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;IMG __jive_id="66510" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66510_pastedImage_2.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;The breakdown of the "Optimized_wo-TE_TX":&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;IMG __jive_id="66511" class="image-3 jive-image" height="284" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66511_pastedImage_3.png" width="492" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;IMG __jive_id="66512" class="jive-image image-4" height="390" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66512_pastedImage_4.png" width="497" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;IMG __jive_id="66513" class="image-5 jive-image" height="341" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66513_pastedImage_5.png" width="497" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Does not show anything that could cause it behave the way it does.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Same goes for the original "Optimized" and "Basic".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;The update that triggered this behavior is 635183954 on one of the management servers prepped for deployment:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;IMG __jive_id="66514" class="image-6 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66514_pastedImage_6.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;And the same update caused same issues in another POC environment:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;IMG __jive_id="66515" class="image-7 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66515_pastedImage_7.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Switch to version" earlier than 63513954, after application of that update, does not revert protections in "Basic", "Optimized" and clone of "Optimized" to "Detect" mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Profile cleanup" with "Remove all user modified" does not revert it to normal state as well.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-9 jive-image" height="317" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66518_pastedImage_3.png" width="490" /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Has anyone seen similar behavior before or are seeing it now?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Vladimir&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 01:37:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2724#M102315</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-06-19T01:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2725#M102316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The reason why those are in Inactive is due to the tag "Threat Prevalence:Rare". All protections with Confidence:Low are tagged with "Threat Prevalence:Rare". The 2 profiles that you mentioned have "Threat Prevalence:Rare" in the Protections To Deactivate section.&lt;/P&gt;&lt;P&gt;I want to thank &lt;A href="https://community.checkpoint.com/migrated-users/54886"&gt;Raz Shlomo&lt;/A&gt;&amp;nbsp;for explaining.&amp;nbsp;Let's continue discussing these questions over this thread.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 16:09:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2725#M102316</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-06-19T16:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2726#M102317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;There is something&amp;nbsp;I didn't mention.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;The protections that are received the first IPS Update in every Management Domain, you know, when you jump from the initial 200 to the 9k protections, are&amp;nbsp;&lt;EM style="border: 0px; font-weight: inherit;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;not&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;marked in Detect(Staging). This mechanism also works from the 2nd update and on. The purpose was to&amp;nbsp;spare the need to clean&amp;nbsp;the staging status from the 9k-200 protections that you download initially.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 16:12:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2726#M102317</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-06-19T16:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2727#M102318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://community.checkpoint.com/migrated-users/6703"&gt;Tomer Sole&lt;/A&gt; Sole and &lt;A href="https://community.checkpoint.com/migrated-users/54886"&gt;Raz Shlomo&lt;/A&gt; for expanding on explanation for the protections behavior.&lt;/P&gt;&lt;P&gt;The problem that I have with this, is that there&amp;nbsp;is not a single protection left with "Detect" in the "Optimized" and "Basic" after above mention update irrespective of the confidence level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "Low Confidence" was selected for simplicity and because in the profile definition, it is explicitly states that "Low Confidence" should be in "Detect" mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand their absence from "Detect(Staging)", but after first update, the only modes displayed are "Disabled" and "Protect".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC was able to verify my findings and are reaching out to R&amp;amp;D for information about this behavior.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 16:51:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2727#M102318</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-06-19T16:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2728#M102319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On your second IPS Update and so on, newly downloaded protections will be in Detect(Staging) even if according to the profile they should be in Prevent.&lt;/P&gt;&lt;P&gt;I understand your point regarding the&amp;nbsp;confusion at Low Confidence.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 17:21:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2728#M102319</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-06-19T17:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2729#M102320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;New protections in the second and onward updates are in the&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Detect(Staging), but &lt;STRONG&gt;there are no protections after the first update in "Detect" only mode, regardless of the confidence level, except in the "Strict" profile.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 21:48:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2729#M102320</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-06-20T21:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: What are IPS Staging Protections? And how do we clear them?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2730#M102321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking at your profile settings:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66578_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66579_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66580_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Things are only in Detect if:&lt;/P&gt;&lt;P&gt;- the protection is newly-downloaded AND the IPS Update is not the first one&lt;/P&gt;&lt;P&gt;- Confidence Level is Low AND not tagged with the excluded tags Threat Prevalence:Rare or Threat Prevalence:Obsolete&amp;nbsp; --&amp;gt; which currently means no protection since all low-confidence protections are auto-tagged with Threat Prevalence:Rare.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is good feedback though and we will consider giving more cues in the user interface regarding "final action".&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 04:26:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-IPS-Staging-Protections-And-how-do-we-clear-them/m-p/2730#M102321</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-06-21T04:26:18Z</dc:date>
    </item>
  </channel>
</rss>

