<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP Reputation exception is not working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276312#M105155</link>
    <description>&lt;P&gt;Did you already try the exception option from the log card itself?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Apr 2026 10:23:38 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2026-04-30T10:23:38Z</dc:date>
    <item>
      <title>IP Reputation exception is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276283#M105140</link>
      <description>&lt;P&gt;Hello Mates!!!&lt;/P&gt;&lt;P&gt;I'm trying to bypass an Anti-Bot IP Reputation Prevent on a specific IP address, but no exception I configure seems to take effect. Hoping someone has seen this behavior before.&lt;/P&gt;&lt;P&gt;Environment: &lt;STRONG&gt;R81.20&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Problem&lt;BR /&gt;&lt;/STRONG&gt;In SmartConsole logs I see Prevent entries from blade Anti-Bot, Protection Type IP Reputation, against destination 13.107.138.10 - a Microsoft IP belonging to subnet 13.107.136.0/22, which is part of the &lt;STRONG&gt;Office 365 Services&lt;/STRONG&gt; Updatable Object (verified by checking the &lt;EM&gt;office365.C&lt;/EM&gt; file on the gateway).&lt;/P&gt;&lt;P&gt;The matched rule is &lt;STRONG&gt;IPS.TO Internet &lt;/STRONG&gt;(corresponding to Threat Prevention policy).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IP Reputation.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34153iD9198C25A32F5B25/image-size/large?v=v2&amp;amp;px=999" role="button" title="IP Reputation.png" alt="IP Reputation.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Since this IP is in a Microsoft-published range I want to also exclude it from Anti-Bot IP Reputation enforcement.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What I tried&lt;/STRONG&gt;&lt;BR /&gt;I configured a Global Exception below:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Protected Scope: &lt;STRONG&gt;Any&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Source: &lt;STRONG&gt;Any&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Destination: &lt;STRONG&gt;13.107.138.10&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Protection/Site/File/Blade: &lt;STRONG&gt;Anti-Virus, IPS, Anti-Bot&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Action: &lt;STRONG&gt;Inactive&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Track: &lt;STRONG&gt;Log&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The log still shows Prevent. The Matched Rules tab in the log details shows only the parent rule &lt;STRONG&gt;IPS.TO Internet&lt;/STRONG&gt; - no reference to the exception.&lt;BR /&gt;I then tried this additional configuration, with the same result (no match): Action set to &lt;STRONG&gt;Detect&lt;/STRONG&gt; instead of &lt;STRONG&gt;Inactive&lt;/STRONG&gt; (based on the suggestion in this thread: &lt;A title="IPS exception not working" href="https://community.checkpoint.com/t5/Threat-Prevention/IPS-exception-not-working/td-p/49664" target="_blank" rel="noopener"&gt;IPS exception not working&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;The policy was properly installed via &lt;EM&gt;Install Policy -&amp;gt; Threat Prevention&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Questions&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is there something specific about how Anti-Bot IP Reputation handles exceptions that I'm missing? Does IP Reputation enforcement happen at a different level than the standard Threat Prevention policy evaluation, bypassing exceptions altogether?&lt;/LI&gt;&lt;LI&gt;Has anyone successfully bypassed an Anti-Bot IP Reputation Prevent on a specific destination via Threat Prevention exceptions in R81.20? If so, what was the working configuration?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any guidance is much appreciated. Screenshots attached.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 22:52:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276283#M105140</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2026-04-29T22:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: IP Reputation exception is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276298#M105145</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;We are experiencing the same issue when trying to bypass Anti-Bot IP Reputation for part of a non-Microsoft website. Unfortunately, we have not been able to exclude the IP address in any way.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;On our gateway, Threat Prevention is configured in Autonomous Policy mode.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 08:00:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276298#M105145</guid>
      <dc:creator>cRealix</dc:creator>
      <dc:date>2026-04-30T08:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: IP Reputation exception is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276302#M105148</link>
      <description>&lt;P&gt;Is the IP part of an IOC feed you have configured? Is there more information in the log card that might help here?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 08:56:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276302#M105148</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-04-30T08:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: IP Reputation exception is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276304#M105150</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;considering the operating logic of the Threat Prevention component, I could assume bypassing the issue by creating a new &lt;STRONG&gt;Profile&lt;/STRONG&gt;, excluding the &lt;STRONG&gt;IP Reputation&lt;/STRONG&gt; protection for it&lt;BR /&gt;(&lt;STRONG&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/CP_R81.20_ThreatPrevention_AdminGuide.pdf" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/CP_R81.20_ThreatPrevention_AdminGuide.pdf&lt;/A&gt;&lt;/STRONG&gt;).&lt;BR /&gt;&lt;BR /&gt;After that, I could create a custom rule for the affected traffic and apply the previously created profile to that rule.&lt;BR /&gt;&lt;BR /&gt;Maybe it would work but I'd like to have your thoughts about this topic.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 08:59:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276304#M105150</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2026-04-30T08:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: IP Reputation exception is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276310#M105153</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;no, it doesn’t appear that an IoC is involved here:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IP Reputation-01.png" style="width: 988px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34156i58479F90229FD3B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="IP Reputation-01.png" alt="IP Reputation-01.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When IoC is involved, it is reported in log &lt;EM&gt;(Indicator Name)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IP Reputation-02.png" style="width: 982px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34157i311AA66A042F0FFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="IP Reputation-02.png" alt="IP Reputation-02.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 09:29:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276310#M105153</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2026-04-30T09:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: IP Reputation exception is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276311#M105154</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;SPAN&gt;Thank you for the idea.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but in Threat Prevention,&amp;nbsp;Autonomous Policy mode you cannot change the profile of the gateway.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 09:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276311#M105154</guid>
      <dc:creator>cRealix</dc:creator>
      <dc:date>2026-04-30T09:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: IP Reputation exception is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276312#M105155</link>
      <description>&lt;P&gt;Did you already try the exception option from the log card itself?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 10:23:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276312#M105155</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-04-30T10:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: IP Reputation exception is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276313#M105156</link>
      <description>&lt;P&gt;Yep, but I get the error: “&lt;EM&gt;Failed to add exception.&lt;/EM&gt;”&lt;/P&gt;&lt;P&gt;Where would the exception be added when it is performed from the card?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 11:40:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276313#M105156</guid>
      <dc:creator>cyberluke365</dc:creator>
      <dc:date>2026-04-30T11:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: IP Reputation exception is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276351#M105172</link>
      <description>&lt;P&gt;OK. The reason I asked is that the IOC blocks are done in SecureXL and as such are not processed in the policy so exceptions don't match. This might be the case for the basic IP Reputation as well but I can't say for sure. Might be one for TAC to get to the bottom of.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2026 01:52:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Reputation-exception-is-not-working/m-p/276351#M105172</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-05-01T01:52:51Z</dc:date>
    </item>
  </channel>
</rss>

