<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw samp stopped working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/118956#M16840</link>
    <description>&lt;P&gt;How many samp rules do you have?&lt;BR /&gt;Also what version/JHF level?&lt;/P&gt;</description>
    <pubDate>Thu, 20 May 2021 17:59:44 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-05-20T17:59:44Z</dc:date>
    <item>
      <title>fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/118633#M16792</link>
      <description>&lt;P&gt;I have a ticket open, but thought I would ask here also...&lt;/P&gt;&lt;P&gt;We have been using the ip blocklist feature from sk103154 across all our gateways for some time, and it was working great. Today I found it is not working as expected.&lt;/P&gt;&lt;P&gt;We run the script on the management station every day to enable the feature on the remote gateways, and we have a list of feeds that we use.&lt;/P&gt;&lt;P&gt;One of them is a custom list we maintain.&lt;/P&gt;&lt;P&gt;When I run the script, I get this response from the gateway&lt;/P&gt;&lt;P&gt;ip_block: Malicious IP blocking mechanism is ON&lt;/P&gt;&lt;P&gt;which is the expected result, but when I run the command&lt;/P&gt;&lt;P&gt;fw samp get | grep threatcloud_ip_block | grep 185.53.179.28&lt;/P&gt;&lt;P&gt;I get no result&lt;/P&gt;&lt;P&gt;the log on the gateway says this&lt;/P&gt;&lt;P&gt;Tue May 18 07:58:08 -04 2021 update_feeds&lt;BR /&gt;Tue May 18 07:58:08 -04 2021 updating https://xxxx/blacklist.txt&lt;BR /&gt;Tue May 18 07:58:08 -04 2021 Not using proxy&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 LAST_UPDATE = Last-Modified:Tue18May202111:28:55GMT&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 last_update new = Last-Modified:Tue18May202111:28:55GMT&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 last_update old = Last-Modified:Tue18May202111:28:55GMT&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 old_timeout = 1621337889&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 new_timeout_sec = 1621339089&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 file name = /opt/CPsuite-R80.40/fw1/database/httpsxxxxblacklisttxt&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 last_update_delta = 1260&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 samp_rule_timeout = 3600&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 samp_delta = 2400&lt;BR /&gt;Tue May 18 07:58:09 -04 2021 https://xxxx/blacklist.txt: feed is up to date&lt;/P&gt;&lt;P&gt;and if I CAT the file I see this&lt;/P&gt;&lt;P&gt;add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:45.61.138.171 pkt-rate 0&lt;BR /&gt;add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:45.84.0.127 pkt-rate 0&lt;BR /&gt;add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:212.109.221.205 pkt-rate 0&lt;BR /&gt;add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:185.243.214.107 pkt-rate 0&lt;BR /&gt;add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:104.247.81.52 pkt-rate 0&lt;BR /&gt;add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:99.83.154.118 pkt-rate 0&lt;BR /&gt;add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:185.53.177.31 pkt-rate 0&lt;BR /&gt;add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:185.53.178.30 pkt-rate 0&lt;BR /&gt;add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:185.53.179.28 pkt-rate 0&lt;/P&gt;&lt;P&gt;which includes the entry I am looking for&lt;/P&gt;&lt;P&gt;Also if I run the command locally, it works&lt;/P&gt;&lt;P&gt;fw samp add -a d -l r -t 3600 -c threatcloud_ip_block quota service any source range:185.53.179.28 pkt-rate 0&lt;/P&gt;&lt;P&gt;fw samp get | grep threatcloud_ip_block | grep 185.53.179.28&lt;/P&gt;&lt;P&gt;operation=add uid=&amp;lt;60a3b4ca,00000000,058ec3a1,000052d4&amp;gt; target=all timeout=3578 action=drop log=log comment=threatcloud_ip_block service=any source=range:185.53.179.28 pkt-rate=0 req_type=quota&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 12:39:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/118633#M16792</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-05-18T12:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/118956#M16840</link>
      <description>&lt;P&gt;How many samp rules do you have?&lt;BR /&gt;Also what version/JHF level?&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 17:59:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/118956#M16840</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-20T17:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119066#M16848</link>
      <description>&lt;P&gt;We have lots.&lt;/P&gt;&lt;P&gt;We run the script to tell the gateways to load the IP lists from website, and we list a number of websites. I have not counted how many IP addresses in total, but this used to be working as far as we could tell&lt;/P&gt;&lt;P&gt;R80.40, JHF102&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 14:19:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119066#M16848</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-05-21T14:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119076#M16850</link>
      <description>&lt;P&gt;What version of code are you using?&amp;nbsp; There have been many changes to these DoS tools in the recent releases, including the phasing out of &lt;STRONG&gt;fw samp&lt;/STRONG&gt; in favor of &lt;STRONG&gt;fwaccel dos&lt;/STRONG&gt;, which you should definitely migrate to if it is available in your release.&lt;/P&gt;
&lt;P&gt;Are you including a &lt;STRONG&gt;flush=true&lt;/STRONG&gt; argument with each individual &lt;STRONG&gt;fw samp&lt;/STRONG&gt; command or at least with the last one in the script sequence?&amp;nbsp; That is required for the &lt;STRONG&gt;fw samp&lt;/STRONG&gt; rules to actually take effect.&amp;nbsp; &lt;STRONG&gt;fwaccel dos&lt;/STRONG&gt; does the equivalent of &lt;STRONG&gt;flush=true&lt;/STRONG&gt; for every command issued by default.&amp;nbsp;&amp;nbsp;Also be aware that by default DoS rules will only be applied to traffic traversing external interfaces unless you specify otherwise.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 15:31:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119076#M16850</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-21T15:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119077#M16851</link>
      <description>&lt;P&gt;R80.40&lt;/P&gt;&lt;P&gt;We are using the script from&amp;nbsp;&lt;SPAN&gt;sk103154&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I am not aware if it has been updated with the new commands&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 15:36:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119077#M16851</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-05-21T15:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119122#M16855</link>
      <description>&lt;P&gt;I would review the script you're using to verify it's using the newer commands as mentioned by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;.&lt;BR /&gt;I believe the syntax is even similar, so it may be possible (with a couple changes) to change over to fwaccel dos.&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 23:36:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119122#M16855</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-21T23:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119137#M16856</link>
      <description>&lt;P&gt;A search for&amp;nbsp;&lt;STRONG&gt;fwaccel dos&lt;/STRONG&gt;&amp;nbsp;leads me to a CLI reference guide that describes this&amp;nbsp;&lt;/P&gt;&lt;P&gt;fwaccel [-i &amp;lt;SecureXL ID&amp;gt;] dos&lt;/P&gt;&lt;P&gt;blacklist &amp;lt;options&amp;gt;&lt;/P&gt;&lt;P&gt;but if I run that command on the gateway I get this&lt;/P&gt;&lt;P&gt;fwaccel dos blacklist -s&lt;BR /&gt;The deny list is empty&lt;BR /&gt;Note: this command is deprecated (see "fwaccel dos deny").&lt;/P&gt;</description>
      <pubDate>Sat, 22 May 2021 08:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119137#M16856</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-05-22T08:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119235#M16869</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;The cache file exists in fwdir\database\cache.bip contains last modified for each feed, GW should load new update every 20 min&lt;BR /&gt;In case of you have new IP, the new feed should load in ~20 Min&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If this was not the case please open a support ticket with your information.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Rachel&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 09:57:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119235#M16869</guid>
      <dc:creator>rachelda</dc:creator>
      <dc:date>2021-05-24T09:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119236#M16870</link>
      <description>&lt;P&gt;I have a ticket open&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 09:59:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/119236#M16870</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-05-24T09:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/120289#M17030</link>
      <description>&lt;P&gt;This was resolved on a call with TAC and others this morning&lt;/P&gt;&lt;P&gt;The text file on the remote webserver had a space after one of the IP addresses, and this prevents it from working correctly.&lt;/P&gt;&lt;P&gt;Removing the space means that it is working again.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 13:15:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/120289#M17030</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2021-06-03T13:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: fw samp stopped working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/120297#M17036</link>
      <description>&lt;P&gt;Thanks for the follow-up, that is a subtle one for sure.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 14:05:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-samp-stopped-working/m-p/120297#M17036</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-06-03T14:05:49Z</dc:date>
    </item>
  </channel>
</rss>

