<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Sandblast replace IPS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8340#M14106</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sandblast and IPS look for different types of threats and it is recommended you deploy both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS is looking at network traffic in general, preventing threats that&amp;nbsp;can occur due to malicious use of known flaws.&lt;/P&gt;&lt;P&gt;For example, there are attacks specifically against the SMB protocol that made the news recently.&lt;/P&gt;&lt;P&gt;With updated signatures and Security Gateways in the proper locations, those sorts of attacks can be prevented.&lt;/P&gt;&lt;P&gt;This is, of course, just one of thousands of examples.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SandBlast is looking at Office and PDF files to see if they are malicious through emulation.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not something IPS is designed to handle.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Likewise, Sandblast isn't looking at things like the SMB protocol.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Oct 2017 15:50:33 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-10-30T15:50:33Z</dc:date>
    <item>
      <title>Can Sandblast replace IPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8339#M14105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If we have deployed Sand blaster at the gateway then why there is a need to enable IPS blade ?&amp;nbsp; I want to know whether we need both or not ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Oct 2017 06:46:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8339#M14105</guid>
      <dc:creator>santosh_sahoo</dc:creator>
      <dc:date>2017-10-30T06:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can Sandblast replace IPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8340#M14106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sandblast and IPS look for different types of threats and it is recommended you deploy both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS is looking at network traffic in general, preventing threats that&amp;nbsp;can occur due to malicious use of known flaws.&lt;/P&gt;&lt;P&gt;For example, there are attacks specifically against the SMB protocol that made the news recently.&lt;/P&gt;&lt;P&gt;With updated signatures and Security Gateways in the proper locations, those sorts of attacks can be prevented.&lt;/P&gt;&lt;P&gt;This is, of course, just one of thousands of examples.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SandBlast is looking at Office and PDF files to see if they are malicious through emulation.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not something IPS is designed to handle.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Likewise, Sandblast isn't looking at things like the SMB protocol.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Oct 2017 15:50:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8340#M14106</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-30T15:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can Sandblast replace IPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8341#M14107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very clear answer &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS is looking for a wide variety of known network attacks of different kinds. Sandblast is looking for unknown (and of course also known) malware files. I would also add that Sandblast looks for many types of files in addition to Office and PDF. For instance, for Sandblast Threat Emulation exe, swf, jar, archives...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Nov 2017 18:40:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8341#M14107</guid>
      <dc:creator>Victor_MR</dc:creator>
      <dc:date>2017-11-27T18:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can Sandblast replace IPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8342#M14108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this still true with R80.10 or R80.20 using sandblast ? I thought this may have changed with everything integrated within Threat cloud, am i wrong in thinking that way ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2019 21:48:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8342#M14108</guid>
      <dc:creator>Ravi_Madhu</dc:creator>
      <dc:date>2019-02-07T21:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can Sandblast replace IPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8343#M14109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The logic I described above hasn't changed in R80.x.&lt;/P&gt;&lt;P&gt;In general, the different Software Blades are meant to work together to provide comprehensive threat prevention.&lt;/P&gt;&lt;P&gt;This is why we sell the majority of them together in a single set versus make them available "a-la carte."&lt;/P&gt;&lt;P&gt;That said, we also offer the flexibility to not enable specific features.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2019 06:50:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Sandblast-replace-IPS/m-p/8343#M14109</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-08T06:50:41Z</dc:date>
    </item>
  </channel>
</rss>

