<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SmartEvent block action hit SAM limitation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-block-action-hit-SAM-limitation/m-p/152195#M25339</link>
    <description>&lt;P&gt;Pretty sure fw samp also has a (likely higher) limit, so not sure moving it to that mechanism is the right answer.&lt;BR /&gt;In any case, this probably requires an RFE to come up with the best approach.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jul 2022 15:17:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-07-01T15:17:31Z</dc:date>
    <item>
      <title>SmartEvent block action hit SAM limitation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-block-action-hit-SAM-limitation/m-p/151435#M24728</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For a while we had SmartEvents enabled and for certain "unwanted activities/traffic like scans or others" and we were triggering a block for 1 hour to 8 hours.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All was good for a while, until we noticed some "Failed to add the following dynamic (SAM) rule" in logs. While investigating we found that the SAM is somehow limited to 1000Kbyte, and in some situations we were filling that quickly.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17001i0F72709E5953D73F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So we were checking for a while and whenever we were seeing the "error" in logs we manually purged the SAM rules.&lt;/P&gt;
&lt;P&gt;As this didn't pleased us, tedious process, we paused the SmartEvent .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still we want to take this back, as it's adding some extra protection in some cases, nowadays is more like a-must-have&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt; .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So we looked into a way to get that activated again, and we sketched a process, to get the SmartEvent event-data being sent via a script to a server, where we extract the fault IP's and feed them into an Generic DataCenter Object (this was funny to implement - I'll have another topic on it) and use the content into a FWL rule that blocks those IP's . We did this in order to have same "automation" like with SAM rules, and not needing to intervene too much on the policies/rules .&lt;/P&gt;
&lt;P&gt;Is this a correct approach ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anyone can enlighten us on the SAM rules limitation, and if there is another way we can address SmartEvents actions, would appreciate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 09:14:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-block-action-hit-SAM-limitation/m-p/151435#M24728</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-22T09:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent block action hit SAM limitation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-block-action-hit-SAM-limitation/m-p/152057#M25140</link>
      <description>&lt;P&gt;SAM rules are a legacy mechanism that I'm sure has some lower limits to it than some of the newer mechanisms (fw samp) that perform a similar task.&lt;BR /&gt;What you're doing (piping into a Generic Datacenter object) is a clever way to solve the problem.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 20:08:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-block-action-hit-SAM-limitation/m-p/152057#M25140</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-29T20:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent block action hit SAM limitation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-block-action-hit-SAM-limitation/m-p/152109#M25186</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;for confirming this.&lt;/P&gt;
&lt;P&gt;Is there any plan to change SmartEvents and make is use "&lt;SPAN&gt;fw samp&lt;/SPAN&gt;" for autoblocking ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 10:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-block-action-hit-SAM-limitation/m-p/152109#M25186</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-30T10:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent block action hit SAM limitation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-block-action-hit-SAM-limitation/m-p/152195#M25339</link>
      <description>&lt;P&gt;Pretty sure fw samp also has a (likely higher) limit, so not sure moving it to that mechanism is the right answer.&lt;BR /&gt;In any case, this probably requires an RFE to come up with the best approach.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 15:17:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-block-action-hit-SAM-limitation/m-p/152195#M25339</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-01T15:17:31Z</dc:date>
    </item>
  </channel>
</rss>

