<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Core Inspection and Custom Policy Exception Rule in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206174#M38947</link>
    <description>&lt;P&gt;There are really 3 kinds of what most administrators would consider IPS Protections or "Signatures", each with their own separate exception mechanism.&amp;nbsp; Adding an exception in one of these categories will not impact the other two.&amp;nbsp; Trying to manually add an exception in one of these three categories will almost always be in the wrong one and not do what you want, so the recommendation is to add them by clicking the "Add Exception..." hyperlink in the log card which will always take you to the correct exception category:&lt;/P&gt;
&lt;P&gt;1) &lt;EM&gt;Inspection Settings&lt;/EM&gt; - part of Access Control/Firewall blade and enforces secure protocol behavior (146 fixed items)&lt;/P&gt;
&lt;P&gt;2) &lt;EM&gt;IPS ThreatCloud Protections&lt;/EM&gt; - Typical IPS blade protections that look for a certain known exploit, and can be updated and added onto with updates from the ThreatCloud (12,800+ items)&lt;/P&gt;
&lt;P&gt;3) &lt;EM&gt;IPS Core Activations&lt;/EM&gt; - 39 special signatures that for technical reasons straddle Access Control and Threat Prevention and can be notoriously difficult to deal with (39 fixed items)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Feb 2024 13:39:12 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2024-02-15T13:39:12Z</dc:date>
    <item>
      <title>IPS Core Inspection and Custom Policy Exception Rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206105#M38932</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quick question,&amp;nbsp; What is the difference between adding an exception rule in Shared Policies-&amp;gt;Inspection Settings-&amp;gt;add exception and&amp;nbsp; Threat Prevention -&amp;gt; Custom Policy-&amp;gt; Add exception&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 16:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206105#M38932</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2024-02-14T16:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Core Inspection and Custom Policy Exception Rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206113#M38933</link>
      <description>&lt;H1&gt;Inspection Settings - General&lt;/H1&gt;
&lt;P class="Procedure_Heading"&gt;What can I do here?&lt;/P&gt;
&lt;P&gt;Use this window to view&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_tp variable"&gt;Threat Prevention&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;protections and their settings.&lt;/P&gt;
&lt;P&gt;For configuring individual inspections, see: Inspection Settings&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Text_Box_Outer_Border" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Text_Box_Outer_Border-Body-Body1"&gt;
&lt;TD class="TableStyle-TP_Table_Text_Box_Outer_Border-BodyF--Body1"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the_rock_0-1707927767930.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24503i3B61EBDBA3AF57AA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="the_rock_0-1707927767930.png" alt="the_rock_0-1707927767930.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Text_Box_Outer_Border-BodyD--Body1"&gt;
&lt;P&gt;&lt;STRONG&gt;Getting Here&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_set variable"&gt;Manage &amp;amp; Settings&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; Blades &amp;gt; General &amp;gt; Inspection Settings &amp;gt; General&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H2&gt;&lt;A name="Inspection_Settings" data-mc-generated-bookmark="TOC" target="_blank"&gt;&lt;/A&gt;Inspection Settings&lt;/H2&gt;
&lt;P&gt;You can configure inspection settings for the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_fwcap variable"&gt;Firewall&lt;/SPAN&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Deep packet inspection settings&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Protocol parsing inspection settings&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_Other.tp_voip variable"&gt;VoIP&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;packet inspection settings&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sms variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/0H3yqvdWWDGUIa-i_DgWfw2.htm?cshid=0H3yqvdWWDGUIa-i_DgWfw2#" data-mc-state="closed" data-aria-describedby="221ebbce-3088-4e23-a51b-413f4e58161f" target="_blank"&gt;Security Management Server&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the_rock_1-1707927767978.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24504i3E1CA47D2B112DDC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="the_rock_1-1707927767978.gif" alt="the_rock_1-1707927767978.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;comes with two preconfigured inspection profiles for the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_fwcap variable"&gt;Firewall&lt;/SPAN&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Default Inspection&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Recommended Inspection&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When you configure a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/0H3yqvdWWDGUIa-i_DgWfw2.htm?cshid=0H3yqvdWWDGUIa-i_DgWfw2#" data-mc-state="closed" data-aria-describedby="dae14eee-876b-410b-814a-64b3fd9171a0" target="_blank"&gt;Security Gateway&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the_rock_2-1707927767979.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24502i85EEEE0749A748A7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="the_rock_2-1707927767979.gif" alt="the_rock_2-1707927767979.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Default Inspection&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;profile is enabled for it. You can also assign the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Recommended Inspection&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;profile to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;, or to create a custom profile and assign it to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;To activate the Inspection Settings, install the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_access variable"&gt;Access Control&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Policy.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Note"&gt;Note&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- In a pre-&lt;SPAN class="mc-variable Vars_Versions.r_hero variable"&gt;R80&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_con variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/0H3yqvdWWDGUIa-i_DgWfw2.htm?cshid=0H3yqvdWWDGUIa-i_DgWfw2#" data-mc-state="closed" data-aria-describedby="13e35253-25e1-4272-bc71-445349eace41" target="_blank"&gt;SmartConsole&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the_rock_3-1707927767980.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24505iB3E430741024F060/image-size/medium?v=v2&amp;amp;px=400" role="button" title="the_rock_3-1707927767980.gif" alt="the_rock_3-1707927767980.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;, Inspection Settings are configured as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ips variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/0H3yqvdWWDGUIa-i_DgWfw2.htm?cshid=0H3yqvdWWDGUIa-i_DgWfw2#" data-mc-state="closed" data-aria-describedby="406db8e8-32d6-4252-9e3a-32e7656bb7be" target="_blank"&gt;IPS&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the_rock_4-1707927767980.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24506i67EB529BBA15B900/image-size/medium?v=v2&amp;amp;px=400" role="button" title="the_rock_4-1707927767980.gif" alt="the_rock_4-1707927767980.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Protections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*****************************************************************&lt;/P&gt;
&lt;P&gt;Exception is more to do with omitting, if you will, specific subnet/group from being "checked" or exempted from specific IPS or av/ab blades protections&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thats at least how I understand it, but if Im wrong, Im sure someone will correct me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 16:26:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206113#M38933</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-14T16:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Core Inspection and Custom Policy Exception Rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206129#M38936</link>
      <description>&lt;P&gt;It looks complicated, but if I want to make an exception for ISP, do I need to do it in Custom policy - add exception rule or shared policy - inspection settings - add exception?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 20:00:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206129#M38936</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2024-02-14T20:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Core Inspection and Custom Policy Exception Rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206134#M38938</link>
      <description>&lt;P&gt;Its its strictly IPS, then you do it from custom policy field. The inspection stuff is mostly for deep packet inspection, I would say. Thats what I remember from old says, even R55 version. It was way different of course, but same principle.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 20:27:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206134#M38938</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-14T20:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Core Inspection and Custom Policy Exception Rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206174#M38947</link>
      <description>&lt;P&gt;There are really 3 kinds of what most administrators would consider IPS Protections or "Signatures", each with their own separate exception mechanism.&amp;nbsp; Adding an exception in one of these categories will not impact the other two.&amp;nbsp; Trying to manually add an exception in one of these three categories will almost always be in the wrong one and not do what you want, so the recommendation is to add them by clicking the "Add Exception..." hyperlink in the log card which will always take you to the correct exception category:&lt;/P&gt;
&lt;P&gt;1) &lt;EM&gt;Inspection Settings&lt;/EM&gt; - part of Access Control/Firewall blade and enforces secure protocol behavior (146 fixed items)&lt;/P&gt;
&lt;P&gt;2) &lt;EM&gt;IPS ThreatCloud Protections&lt;/EM&gt; - Typical IPS blade protections that look for a certain known exploit, and can be updated and added onto with updates from the ThreatCloud (12,800+ items)&lt;/P&gt;
&lt;P&gt;3) &lt;EM&gt;IPS Core Activations&lt;/EM&gt; - 39 special signatures that for technical reasons straddle Access Control and Threat Prevention and can be notoriously difficult to deal with (39 fixed items)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 13:39:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Core-Inspection-and-Custom-Policy-Exception-Rule/m-p/206174#M38947</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-02-15T13:39:12Z</dc:date>
    </item>
  </channel>
</rss>

