<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does Threat-Prevention exception inherit DNS-Trap property of profiles in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-Threat-Prevention-exception-inherit-DNS-Trap-property-of/m-p/124657#M17988</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The title of this post already expresses my question pretty well.&lt;BR /&gt;I have a situation where I must maintain visiblity for the "Reputation Domains" protection of a few specific servers, without it triggering the Malware DNS-Trap for those specific servers only.&lt;/P&gt;&lt;P&gt;I have possible solutions in mind such as creating a copy of the profile, disabling DNS-trap on it, and putting the servers only under this new profile. But those feel like sloppy solutions with too much ugly configuration to be justified.&lt;/P&gt;&lt;P&gt;Which brings me to my question, If I were to create an exception bound to this profile with the action detect. Will the DNS trap still be triggered as it would use the parameters of the profile?&lt;BR /&gt;One step further, if I were to include it in a global exception, would it also inherit the action? Because the global exception sort-off appends an exception but to every existing profile, I'd expect the same behaviour as with an exception to a profile specifically.&lt;/P&gt;&lt;P&gt;Thanks in advance for your input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running R80.40 on Quantum 15400 appliances&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jul 2021 10:40:02 GMT</pubDate>
    <dc:creator>robin_van_royen</dc:creator>
    <dc:date>2021-07-22T10:40:02Z</dc:date>
    <item>
      <title>Does Threat-Prevention exception inherit DNS-Trap property of profiles</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-Threat-Prevention-exception-inherit-DNS-Trap-property-of/m-p/124657#M17988</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The title of this post already expresses my question pretty well.&lt;BR /&gt;I have a situation where I must maintain visiblity for the "Reputation Domains" protection of a few specific servers, without it triggering the Malware DNS-Trap for those specific servers only.&lt;/P&gt;&lt;P&gt;I have possible solutions in mind such as creating a copy of the profile, disabling DNS-trap on it, and putting the servers only under this new profile. But those feel like sloppy solutions with too much ugly configuration to be justified.&lt;/P&gt;&lt;P&gt;Which brings me to my question, If I were to create an exception bound to this profile with the action detect. Will the DNS trap still be triggered as it would use the parameters of the profile?&lt;BR /&gt;One step further, if I were to include it in a global exception, would it also inherit the action? Because the global exception sort-off appends an exception but to every existing profile, I'd expect the same behaviour as with an exception to a profile specifically.&lt;/P&gt;&lt;P&gt;Thanks in advance for your input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running R80.40 on Quantum 15400 appliances&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 10:40:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-Threat-Prevention-exception-inherit-DNS-Trap-property-of/m-p/124657#M17988</guid>
      <dc:creator>robin_van_royen</dc:creator>
      <dc:date>2021-07-22T10:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Does Threat-Prevention exception inherit DNS-Trap property of profiles</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-Threat-Prevention-exception-inherit-DNS-Trap-property-of/m-p/124826#M18020</link>
      <description>&lt;P&gt;As far as I know, exceptions for this specific protection should work.&lt;BR /&gt;That said, we do log as detect even when it's preventing prior to R81.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Threat-Prevention/Threat-Prevention-is-Not-Block-DNS-Reputation-Which-Policy-Are/m-p/27139#M818" target="_blank"&gt;https://community.checkpoint.com/t5/Threat-Prevention/Threat-Prevention-is-Not-Block-DNS-Reputation-Which-Policy-Are/m-p/27139#M818&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jul 2021 02:20:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-Threat-Prevention-exception-inherit-DNS-Trap-property-of/m-p/124826#M18020</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-25T02:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Does Threat-Prevention exception inherit DNS-Trap property of profiles</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-Threat-Prevention-exception-inherit-DNS-Trap-property-of/m-p/124878#M18031</link>
      <description>&lt;P&gt;Thank you very much for the feedback.&lt;/P&gt;&lt;P&gt;I have tried the detect rule, and it works like a charm. Now resulting in "action: exception". Also good to know that this categorization as detect is changed for R81.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 07:09:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-Threat-Prevention-exception-inherit-DNS-Trap-property-of/m-p/124878#M18031</guid>
      <dc:creator>robin_van_royen</dc:creator>
      <dc:date>2021-07-26T07:09:27Z</dc:date>
    </item>
  </channel>
</rss>

