<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to exclude IP from SAM rules in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236461#M45852</link>
    <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;Following a big outage we noticed that our main gateways had put their own public IP subnet in the SAM ruleset. How can I prevent this from happening? Is there any way to exclude a subnet from being monitored for suspicious activity?&lt;/P&gt;</description>
    <pubDate>Fri, 20 Dec 2024 08:54:50 GMT</pubDate>
    <dc:creator>demirdag</dc:creator>
    <dc:date>2024-12-20T08:54:50Z</dc:date>
    <item>
      <title>How to exclude IP from SAM rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236461#M45852</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;Following a big outage we noticed that our main gateways had put their own public IP subnet in the SAM ruleset. How can I prevent this from happening? Is there any way to exclude a subnet from being monitored for suspicious activity?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 08:54:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236461#M45852</guid>
      <dc:creator>demirdag</dc:creator>
      <dc:date>2024-12-20T08:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude IP from SAM rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236473#M45856</link>
      <description>&lt;P&gt;I would look at&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk112061" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112061&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to create and view Suspicious Activity Monitoring (SAM) Rules&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to see if -b flag with IP of Security Gateway works.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 12:27:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236473#M45856</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-12-20T12:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude IP from SAM rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236490#M45860</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;. I would double check what you have as per short video I uploaded.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-6366278238112w960h540r412" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6366278238112" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-6366278238112w960h540r412');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/6366278238112"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 14:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236490#M45860</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-20T14:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude IP from SAM rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236516#M45870</link>
      <description>&lt;P&gt;As far as I know, there shouldn’t be anything automatically creating SAM rules against your gateway IP.&lt;BR /&gt;There is nothing preventing you from doing so via the fw sam command, however.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 16:55:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236516#M45870</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-20T16:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude IP from SAM rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236536#M45874</link>
      <description>&lt;P&gt;To prevent your main gateways from including their own public IP subnet in the SAM ruleset, you can exclude specific subnets from being monitored for suspicious activity by configuring exceptions in the SAM rules. Here's how you can do it:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Access the Security Management Server&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Open SmartConsole and connect to your Security Management Server.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Navigate to SAM Settings&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Go to "Logs &amp;amp; Monitor" and open the SmartView Monitor.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Open Suspicious Activity Rules&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Click on the "Suspicious Activity Rules" icon in the toolbar to open the Enforced Suspicious Activity Rules window.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Add an Exception&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Click on "Add" to create a new rule.&lt;/LI&gt;
&lt;LI&gt;In the "Block Suspicious Activity" window, specify the source and destination IP addresses or networks you want to exclude. Use the IP and subnet mask fields to define the subnet you wish to exclude.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Configure the Rule&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Set the action to "Notify" instead of "Block" for the specific subnet you want to exclude.&lt;/LI&gt;
&lt;LI&gt;Set an expiration time for the rule to ensure it doesn't affect performance unnecessarily.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Enforce the Rule&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Click "Enforce" to apply the rule to the selected Security Gateway(s)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 20 Dec 2024 19:27:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-exclude-IP-from-SAM-rules/m-p/236536#M45874</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2024-12-20T19:27:37Z</dc:date>
    </item>
  </channel>
</rss>

