<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question regarding traffic handling? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-regarding-traffic-handling/m-p/248150#M48485</link>
    <description>&lt;P&gt;Please make sure ALL of your Check Point gateways are properly patched/upgraded to fix CVE-2024-24919, not just using the IPS signature for it:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182336" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk182336&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In any case, an Access Policy "accept" followed by a Threat Prevention "drop" is normal since we process Access Policy rules before Threat Prevention.&lt;BR /&gt;Which means the traffic should have been dropped by IPS.&lt;/P&gt;
&lt;P&gt;What evidence does the XDR provide that the relevant traffic wasn't blocked?&lt;/P&gt;</description>
    <pubDate>Mon, 05 May 2025 23:31:09 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-05-05T23:31:09Z</dc:date>
    <item>
      <title>Question regarding traffic handling?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-regarding-traffic-handling/m-p/248126#M48475</link>
      <description>&lt;P&gt;R81.20&lt;/P&gt;
&lt;P&gt;This is concerning CVE-2024-24919.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We applied the hotfix last year for this and all the recommended other steps.&lt;/P&gt;
&lt;P&gt;We use a third party XDR system, and while going through the events from today, I noticed that it says that my Check Point "did not block" traffic related to CVE-2024-24919.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I look at my Check Point logs in Smart Log, I can only see two entries at the same exact time:.&amp;nbsp; One is my firewall blade telling me it let this traffic through.&lt;/P&gt;
&lt;P&gt;The other entry is telling me my IPS rule for CVE-2024-24919 prevented it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm guessing this traffic was blocked by my IPS, but why would this pacet not be "dropped"&amp;nbsp; at the gateway, or is this just a GUI quirk Check Point?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 18:41:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-regarding-traffic-handling/m-p/248126#M48475</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2025-05-05T18:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding traffic handling?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-regarding-traffic-handling/m-p/248134#M48481</link>
      <description>&lt;P&gt;Do you see the CVE in the logs?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 20:07:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-regarding-traffic-handling/m-p/248134#M48481</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-05-05T20:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding traffic handling?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-regarding-traffic-handling/m-p/248150#M48485</link>
      <description>&lt;P&gt;Please make sure ALL of your Check Point gateways are properly patched/upgraded to fix CVE-2024-24919, not just using the IPS signature for it:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182336" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk182336&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In any case, an Access Policy "accept" followed by a Threat Prevention "drop" is normal since we process Access Policy rules before Threat Prevention.&lt;BR /&gt;Which means the traffic should have been dropped by IPS.&lt;/P&gt;
&lt;P&gt;What evidence does the XDR provide that the relevant traffic wasn't blocked?&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 23:31:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-regarding-traffic-handling/m-p/248150#M48485</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-05-05T23:31:09Z</dc:date>
    </item>
  </channel>
</rss>

