<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Searching for IPS protections via ssh in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171290#M31059</link>
    <description>&lt;P&gt;Right and to GET to most important part you need the command : - )&lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2023 18:15:45 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-02-13T18:15:45Z</dc:date>
    <item>
      <title>Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171270#M31021</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Figured would share this in case anyone encounters the same problem. So had issue with customer where certain parts of sites on Azure were not coming up when testing from on prem and we ran debug and discovered it was related to IPS, but had hard time finding out the protection in question. So I saw there is a command you can run via expert mode if you have xeha-decimal value for protection (which we did from the drops) and once we got the protection name, was easy to fix the problem.&lt;/P&gt;
&lt;P&gt;[Expert@quantum-firewall:0]# ips&lt;/P&gt;
&lt;P&gt;Usage:&lt;BR /&gt;ips stat # Display IPS status&lt;BR /&gt;ips on|off # Enable\Disable IPS&lt;BR /&gt;ips bypass stat # Display Bypass Under Load status&lt;BR /&gt;ips bypass on|off # Enable\Disable bypass mode&lt;BR /&gt;ips bypass set cpu|mem low|high &amp;lt;th&amp;gt; # Set bypass thresholds&lt;BR /&gt;ips debug [-e filter] -o &amp;lt;outfile&amp;gt; # Get IPS debugs&lt;BR /&gt;ips refreshcap # Refresh the sample capture repository&lt;BR /&gt;ips stats [&amp;lt;ip_address&amp;gt; -m] [-g &amp;lt;seconds&amp;gt;] [&amp;lt;ip_address&amp;gt; &amp;lt;seconds&amp;gt;] [-h]&lt;BR /&gt;# Print IPS performance and PM statistics&lt;BR /&gt;&lt;STRONG&gt;ips protection &amp;lt;protection_id (hex)&amp;gt; # Display protection name&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Note: IPS CLI configuration is temporary - it will be overridden by the next&lt;BR /&gt;policy installation or boot&lt;BR /&gt;[Expert@quantum-firewall:0]# &lt;STRONG&gt;ips protection 0x82e5656a&lt;/STRONG&gt;&lt;BR /&gt;Web Servers Malicious URL Directory Traversal&lt;BR /&gt;[Expert@quantum-firewall:0]#&lt;/P&gt;
&lt;P&gt;I would say since we saw lots of errors first packet isnt SYN and customer proved this worked fine when NOT traversing the CP cluster, I would say, if you ever see that message, always check threat prevention blades, specially IPS, apart from obvious "culprits"...routing, NAT, sxl : - )&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 20:32:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171270#M31021</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-17T20:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171274#M31022</link>
      <description>&lt;P&gt;Btw, these are drops from zdebug.&lt;/P&gt;
&lt;P&gt;To add this as a side note, no matter what words we used to search for IPS protection in smart console, absolutely nothing worked and we were unable to find the actual protection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;@;436822375;[vs_0];[tid_1];[fw4_1];ips_cmi_handler_match_cb_ex: Packet dir 0, 19 2.168.37.190:63474 -&amp;gt; 10.30.11.17:80 IPP 6 dropped by IPS [reject] , protection_ id=0x82e5656a, protection_name=&amp;lt;GW CLI: ips protection 0x82e5656a&amp;gt;;&lt;BR /&gt;@;436822377;[vs_0];[tid_1];[fw4_1];fw_log_drop_ex: Packet proto=6 192.168.37.190 :63474 -&amp;gt; 10.30.11.17:80 dropped by fwmultik_process_f2p_cookie_inner Reason: PS L Drop: WS&lt;BR /&gt;@;436822379;[vs_0];[tid_1];[fw4_1];fw_log_drop_ex: Packet proto=6 192.168.37.190 :63474 -&amp;gt; 10.30.11.17:80 dropped by fwmultik_process_f2p_cookie_inner Reason: PS L Drop: WS&lt;BR /&gt;@;436822442;[vs_0];[tid_1];[fw4_1];ips_cmi_handler_match_cb_ex: Packet dir 0, 19 2.168.37.190:63424 -&amp;gt; 10.30.11.17:80 IPP 6 dropped by IPS [reject] , protection_ id=0x82e5656a, protection_name=&amp;lt;GW CLI: ips protection &lt;STRONG&gt;0x82e5656a&lt;/STRONG&gt;&amp;gt;;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 17:11:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171274#M31022</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-13T17:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171279#M31023</link>
      <description>&lt;P&gt;I can find it:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="malic.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19593i904B06434D9EBFF3/image-size/large?v=v2&amp;amp;px=999" role="button" title="malic.jpg" alt="malic.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Has even been updated recently...&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 17:23:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171279#M31023</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-13T17:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171280#M31024</link>
      <description>&lt;P&gt;Well, you can find it when I gave full name lol. If you search by the actual words from the debug I attached, you will NOT find it : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 17:24:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171280#M31024</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-13T17:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171286#M31057</link>
      <description>&lt;P&gt;Yes, therefore i use the most important part only...&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 18:09:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171286#M31057</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-13T18:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171289#M31058</link>
      <description>&lt;P&gt;Great tip!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 18:12:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171289#M31058</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-13T18:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171290#M31059</link>
      <description>&lt;P&gt;Right and to GET to most important part you need the command : - )&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 18:15:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171290#M31059</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-13T18:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171292#M31060</link>
      <description>&lt;P&gt;Figured would share since I learned this myself today as well : - )&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 18:18:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171292#M31060</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-13T18:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171311#M31062</link>
      <description>&lt;P&gt;Very nice, thanks for sharing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 19:36:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171311#M31062</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-02-13T19:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171312#M31063</link>
      <description>&lt;P&gt;No worries, any time. I asked my colleague to share this link with TAC engineer, hopefully it saves them some time if they ever encounter this with another customer.&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 19:38:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171312#M31063</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-13T19:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171313#M31064</link>
      <description>&lt;P&gt;Forgot to mention that it is possible to make the offending IPS signature name show up directly in the &lt;STRONG&gt;fw ctl zdebug drop&lt;/STRONG&gt; output by changing variable &lt;STRONG&gt;enable_inspect_debug_compilation&lt;/STRONG&gt; from false to true in GUIdbedit, although doing so will substantially increase the size of the compiled policy sent to the gateway:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60395&amp;amp;partition=Advanced&amp;amp;product=IPS" target="_blank" rel="noopener"&gt;sk60395: How to debug IPS during issues with DCE-RPC traffic&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't done this in quite some time and it may no longer be supported.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 19:49:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171313#M31064</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-02-13T19:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171314#M31065</link>
      <description>&lt;P&gt;Ah, good to know.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 19:49:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171314#M31065</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-13T19:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171357#M31069</link>
      <description>&lt;P&gt;But the command will not be helpfull if you cannot find the protection 8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 07:47:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171357#M31069</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-14T07:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171398#M31075</link>
      <description>&lt;P&gt;So answer this then...based on debug I posted, and ONLY debug, how would you ever figure out what is the IPS protection if you dont run command I gave? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 11:28:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/171398#M31075</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-14T11:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/218846#M41792</link>
      <description>&lt;P&gt;Thanks for the info&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;.&amp;nbsp; I had exactly the same issue today; zdebug gave a hex code which doesn't show up when you search in the protections in SmartConsole.&amp;nbsp; The CLI command told me the protection name, then I found it in SmartConsole using the name.&lt;/P&gt;&lt;P&gt;Interestingly also, these drops did not appear in the logs in SmartConsole, so at first I didn't even think I had an IPS issue until I'd done the zdebug.&amp;nbsp; Not the first time the logs alone don't tell the full story.&amp;nbsp; Or any of the story!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 17:17:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/218846#M41792</guid>
      <dc:creator>madu1</dc:creator>
      <dc:date>2024-06-26T17:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/218847#M41793</link>
      <description>&lt;P&gt;Glad it helped you.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 17:20:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/218847#M41793</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-26T17:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Searching for IPS protections via ssh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/219128#M41873</link>
      <description>&lt;P&gt;The issue about lack of logging a specific IPS protection should probably be raised with TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 15:47:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Searching-for-IPS-protections-via-ssh/m-p/219128#M41873</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-28T15:47:10Z</dc:date>
    </item>
  </channel>
</rss>

