<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling web server security in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/138862#M21141</link>
    <description>&lt;P&gt;Hello &lt;SPAN&gt;Vladimir&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;can you clarify the difference between Accept and Drop in action field?&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jan 2022 11:19:34 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2022-01-19T11:19:34Z</dc:date>
    <item>
      <title>Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51732#M3897</link>
      <description>&lt;P&gt;Hi guys,&lt;BR /&gt;I have a checkpoint firewall with ngtx. I want to enable web security for my web servers (sql injection, cross site scripting etc.). I did this by creating a host of web server and enabled the protections.&lt;/P&gt;&lt;P&gt;Is that all or do I need to add something else somehwere too. In the guide it mentions the following "Enforcement of these protections are dependent on IPS profile" What does that mean?&lt;/P&gt;&lt;P&gt;Also how can I test that these protections are working via some testing method?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 15:42:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51732#M3897</guid>
      <dc:creator>KandarpDesai</dc:creator>
      <dc:date>2019-04-24T15:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51741#M3898</link>
      <description>&lt;P&gt;Protections can be enabled/disabled in your IPS profile and/or your Threat Prevention policy, depending on management and gateway version.&lt;BR /&gt;It would be helpful if you specified the exact steps you followed and provided some screenshots of exactly what you did.&lt;BR /&gt;Also, anytime you make changes to IPS, you need to push the Threat Prevention policy (Access Policy for R77.x Gateways).&lt;BR /&gt;&lt;BR /&gt;As far as testing some of these protections, you can use a tool like Burp Suite.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 16:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51741#M3898</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-24T16:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51748#M3900</link>
      <description>&lt;P&gt;Hi Phoneboy,&lt;/P&gt;&lt;P&gt;Thanks for suggesting BurpSuite, I have applied for a trial.&lt;/P&gt;&lt;P&gt;As for the steps, I did the following&lt;/P&gt;&lt;P&gt;- Created a new host&lt;BR /&gt;- Clicked on Servers&amp;gt;Web server&amp;gt;Protections&lt;BR /&gt;- Protections were enabled already.&lt;BR /&gt;- Pushed the Threat Policy ( exisiting Policy is Scope=Any and Action=Optimized )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Webserver.png" style="width: 498px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/958i06E840DB77A1DC97/image-size/large?v=v2&amp;amp;px=999" role="button" title="Webserver.png" alt="Webserver.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 17:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51748#M3900</guid>
      <dc:creator>KandarpDesai</dc:creator>
      <dc:date>2019-04-24T17:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51928#M3912</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;Kindly help me to know if this is correct. Appreciate the help.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 06:25:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51928#M3912</guid>
      <dc:creator>KandarpDesai</dc:creator>
      <dc:date>2019-04-26T06:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51980#M3915</link>
      <description>&lt;P&gt;What does your Threat Prevention rulebase look like?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 17:03:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51980#M3915</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-26T17:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51984#M3916</link>
      <description>I am curious about this as well. I thought we just need to configure the Profile protection and it will apply; This looks very specific to web server; do we need to configure all the web server object this way?</description>
      <pubDate>Fri, 26 Apr 2019 17:31:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51984#M3916</guid>
      <dc:creator>Cyber_Serge</dc:creator>
      <dc:date>2019-04-26T17:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51989#M3917</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Frank_Yao1,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;to enable the Webserver-protections you have to enable the servertype Webserver and the protections on all your webservers host objects.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 18:43:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51989#M3917</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-04-26T18:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51991#M3919</link>
      <description>&lt;P&gt;Dear PB,&lt;BR /&gt;My threat policy is "ANY" and "OPTIMIZED"&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 18:45:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51991#M3919</guid>
      <dc:creator>KandarpDesai</dc:creator>
      <dc:date>2019-04-26T18:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51995#M3920</link>
      <description>&lt;P&gt;Dear Wolfgang,&lt;/P&gt;&lt;P&gt;I want to confirm if my config is right or not.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 18:55:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/51995#M3920</guid>
      <dc:creator>KandarpDesai</dc:creator>
      <dc:date>2019-04-26T18:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52167#M3935</link>
      <description>This was required pre-R80.x, but I don't believe this is no longer required.</description>
      <pubDate>Mon, 29 Apr 2019 17:17:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52167#M3935</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-29T17:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52168#M3936</link>
      <description>Your configuration is correct (assuming gateway is R80.x).</description>
      <pubDate>Mon, 29 Apr 2019 17:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52168#M3936</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-29T17:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52172#M3937</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, please clarify:&lt;/P&gt;
&lt;P&gt;Are we still required to configure the Web Server objects and their protections individually, or is the "Optimized" profile taking care of that irrespective to the target server?&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Vladimir&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. It is really difficult to track which response is relevant to which thread in the forum unless person is mentioned by name and the excerpt from their post is included in the reply.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 17:46:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52172#M3937</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-04-29T17:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52173#M3938</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I follow Vladimir, there should be a statement for the web security configuration.&lt;/P&gt;&lt;P&gt;I think it is too needed in R80.xx, there are no protections like „SQL injections, cross site scripting, etc. „ in the normal IPS protections.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dameon, please can you clarify if needed or not.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 18:14:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52173#M3938</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-04-29T18:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52174#M3939</link>
      <description>&lt;P&gt;Yes Kandarp, you config looks good.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 18:15:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52174#M3939</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-04-29T18:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52178#M3940</link>
      <description>I'm checking this, but I don't believe it's required.</description>
      <pubDate>Mon, 29 Apr 2019 20:20:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52178#M3940</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-29T20:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52189#M3942</link>
      <description>Checking on all of it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;And yes, I'm aware we need to add indents in threads, but that's turning out to be a bigger problem to solve than it should be.</description>
      <pubDate>Mon, 29 Apr 2019 21:37:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52189#M3942</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-29T21:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52196#M3943</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There two types of protections (or actually three if you count also inspection settings):&lt;/P&gt;
&lt;P&gt;Threat Cloud Protections that are the actual IPS Protections updated from Check Point Threat Cloud. These protections are installed with the Threat Prevention Policy.&lt;/P&gt;
&lt;P&gt;Core Protections are protections that require IPS blade, but are there by default (there are 39 of them or so). These protections are installed with the Access Control Policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Core Protections are assigned directly to the gateways with their profile. You can then select whether you want this specific protection to be assigned to a selected web server or not (if it's a web server related protection). If you know your web servers and have configured them, make sure "Apply to Selected Web Servers" is selected. Otherwise select "Apply to all HTTP Traffic". By clicking View you can view the web servers that you have configured in the host object as a web server.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coreprotect3.PNG" style="width: 697px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1016iDC4B1F98BF243797/image-size/large?v=v2&amp;amp;px=999" role="button" title="coreprotect3.PNG" alt="coreprotect3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 00:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52196#M3943</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2019-04-30T00:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52197#M3944</link>
      <description>&lt;P&gt;Yes you are still required to do that. Those protections have moved to so called core protections that are installed with Access Control Policy. See my full response to this thread.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT: I thought this response would have shown under Vladimir's question. Hmmm...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 00:20:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52197#M3944</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2019-04-30T00:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52206#M3945</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;, how on earth did you get to see the screen from your post above &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ?&lt;/P&gt;
&lt;P&gt;I am pocking in both, R80.20 and R80.30 in Core Protections and all I am seeing is:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1019i3B5A5C04049BA41C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and when editing the selected "HTTP Header Patterns", I am seeing:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1020i5D77AD98B7F0CD67/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which, IMHO, got to mean that the entire scope is protected and that there is no need to cherry-pick the Web Servers.&lt;/P&gt;
&lt;P&gt;Am I looking at this wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 01:25:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52206#M3945</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-04-30T01:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling web server security</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52216#M3946</link>
      <description>&lt;P&gt;Hi Vladimir,&lt;/P&gt;
&lt;P&gt;1. Open a Core Protection&lt;/P&gt;
&lt;P&gt;2. In General Tab double click&amp;nbsp; a profile (e.g. Optimized)&lt;/P&gt;
&lt;P&gt;3. Go to Advanced Tab&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coreprotect1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1022i2723E5C3A51C50DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="coreprotect1.PNG" alt="coreprotect1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 04:05:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enabling-web-server-security/m-p/52216#M3946</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2019-04-30T04:05:24Z</dc:date>
    </item>
  </channel>
</rss>

