<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall setup as Monitor Mode but does not seems to have much logs related to IPS, Anti-Bot&amp;amp in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198663#M37204</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The "track" option for policy rules are set to "Log".&lt;/P&gt;&lt;P&gt;I might found out the cause of it.&lt;/P&gt;&lt;P&gt;The profile "Optimized" is being used. By following the admin guide to set up the gateway in monitor mode, the "Activation Mode" will be needed to change from "Prevent" to "Detect". When changing the default "Optimized" profile, SmartConsole will prompt automatically asking you to create another cloned profile of the default "Optimized" profile since the default profile cannot be modify.&lt;/P&gt;&lt;P&gt;After modified profile had been cloned out, I did not notice that the "Protection" of the IPS Protection are mostly Inactive. After enabled most of the "Protection" of the IPS Protection of the profile then I am able to see some of IPS logs again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-22 223505.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23373i983BA2E7744D8A90/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-22 223505.png" alt="Screenshot 2023-11-22 223505.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate for the help&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Wed, 22 Nov 2023 14:36:06 GMT</pubDate>
    <dc:creator>BigHec</dc:creator>
    <dc:date>2023-11-22T14:36:06Z</dc:date>
    <item>
      <title>Firewall setup as Monitor Mode but does not seems to have much logs related to IPS, Anti-Bot&amp;-virus</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198609#M37192</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Recently I have setup a gateway as Monitor Mode and to capture all the traffics within the network.&lt;/P&gt;&lt;P&gt;I have configured the gateway according these guideline:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Configuring-Single-Security-Gateway-in-Monitor-Mode.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Configuring-Single-Security-Gateway-in-Monitor-Mode.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The gateway has configured a Monitor port and is connected to a switch port configured as SPAN port to mirror all the traffics.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;After monitored for 1 day, we can see the firewall logs are working fine, we able to see all the network traffics.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-22 143244.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23356i8FBE093D98289BA7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-22 143244.png" alt="Screenshot 2023-11-22 143244.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I try to search for logs related to IPS, Anti-Bot and Anti-Virus (Monitor mode so the threat prevention is set as all "Detect")&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1232131132.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23357i2BA972A492A00C82/image-size/large?v=v2&amp;amp;px=999" role="button" title="1232131132.png" alt="1232131132.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Is this a normal behavior? Because this seems like a little less for IPS logs for me. For what i expect is to see more of the threat prevention related logs.&lt;/P&gt;&lt;P&gt;Is there any settings that I've missed out on the gateway?&lt;/P&gt;&lt;P&gt;Appreciate for all the help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 06:46:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198609#M37192</guid>
      <dc:creator>BigHec</dc:creator>
      <dc:date>2023-11-22T06:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall setup as Monitor Mode but does not seems to have much logs related to IPS, Anti-Bot&amp;amp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198610#M37193</link>
      <description>&lt;P&gt;FYI, this gateway previously has internet access but the internet access had been cut off after that. So now the gateway does has Application, IPS, Anti-Bot and Anti-Virus of previous version and not the latest version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Blades Enabled:&lt;/P&gt;&lt;P&gt;Firewall&lt;BR /&gt;Application Control&lt;BR /&gt;URL Filtering&lt;BR /&gt;IPS (Detect Only)&lt;BR /&gt;Anti-Bot&amp;nbsp;(Detect Only)&lt;BR /&gt;Anti-Virus&amp;nbsp;(Detect Only)&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 06:52:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198610#M37193</guid>
      <dc:creator>BigHec</dc:creator>
      <dc:date>2023-11-22T06:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall setup as Monitor Mode but does not seems to have much logs related to IPS, Anti-Bot&amp;amp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198611#M37194</link>
      <description>&lt;P&gt;Starting with the basics what "track" option is set for the policy rules currently, detailed / extended log or other?&lt;/P&gt;
&lt;P&gt;Click on the arrow in the track cell and select more to see additional options e.g.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Track.png" style="width: 314px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23358iF4E63D49BC82BBF5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Track.png" alt="Track.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Typically in monitor mode we won't have things like HTTPS inspection which will also limit visibility into traffic.&lt;/P&gt;
&lt;P&gt;With that said what Threat Prevention Profile is currently used?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 07:01:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198611#M37194</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-22T07:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall setup as Monitor Mode but does not seems to have much logs related to IPS, Anti-Bot&amp;amp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198663#M37204</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The "track" option for policy rules are set to "Log".&lt;/P&gt;&lt;P&gt;I might found out the cause of it.&lt;/P&gt;&lt;P&gt;The profile "Optimized" is being used. By following the admin guide to set up the gateway in monitor mode, the "Activation Mode" will be needed to change from "Prevent" to "Detect". When changing the default "Optimized" profile, SmartConsole will prompt automatically asking you to create another cloned profile of the default "Optimized" profile since the default profile cannot be modify.&lt;/P&gt;&lt;P&gt;After modified profile had been cloned out, I did not notice that the "Protection" of the IPS Protection are mostly Inactive. After enabled most of the "Protection" of the IPS Protection of the profile then I am able to see some of IPS logs again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-22 223505.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23373i983BA2E7744D8A90/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-22 223505.png" alt="Screenshot 2023-11-22 223505.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate for the help&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 14:36:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198663#M37204</guid>
      <dc:creator>BigHec</dc:creator>
      <dc:date>2023-11-22T14:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall setup as Monitor Mode but does not seems to have much logs related to IPS, Anti-Bot&amp;amp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198674#M37207</link>
      <description>&lt;P&gt;Indeed the different IPS profiles have varying activation metrics (confidence/performance etc) for protections which ultimately determines which are inactive etc.&lt;/P&gt;
&lt;P&gt;If you want to also see AppC / URLF logs you will&amp;nbsp; need to also adjust that 'log' option.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 15:10:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198674#M37207</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-22T15:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall setup as Monitor Mode but does not seems to have much logs related to IPS, Anti-Bot&amp;amp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198678#M37208</link>
      <description>&lt;P&gt;Am I unable to see any logs related to AppC/ URLF if the track option is set to "Log"?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 15:16:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198678#M37208</guid>
      <dc:creator>BigHec</dc:creator>
      <dc:date>2023-11-22T15:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall setup as Monitor Mode but does not seems to have much logs related to IPS, Anti-Bot&amp;amp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198680#M37209</link>
      <description>&lt;P&gt;Please refer: &lt;A href="https://support.checkpoint.com/results/sk/sk120536" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk120536&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 15:20:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198680#M37209</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-22T15:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall setup as Monitor Mode but does not seems to have much logs related to IPS, Anti-Bot&amp;amp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198772#M37225</link>
      <description>&lt;P&gt;Independent of your Threat Prevention configuration, traffic cannot actually be prevented if you’re only receiving the traffic via a span/monitor port.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 14:19:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-setup-as-Monitor-Mode-but-does-not-seems-to-have-much/m-p/198772#M37225</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-23T14:19:41Z</dc:date>
    </item>
  </channel>
</rss>

