<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Detected Sweep Scan originating from source: internal server - destination: empty in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255864#M50105</link>
    <description>&lt;P&gt;Thank you for the reply,&lt;/P&gt;&lt;P&gt;Exceptions are configured in place long time ago. This issue was once-off, unexpected incident.&amp;nbsp;&lt;BR /&gt;It's not clear how to reproduce this incident since we don't have any possible destination or what tool or process initiated that.&lt;/P&gt;&lt;P&gt;Do you have any suggestions?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Aug 2025 08:25:38 GMT</pubDate>
    <dc:creator>RuneSeeker</dc:creator>
    <dc:date>2025-08-25T08:25:38Z</dc:date>
    <item>
      <title>Detected Sweep Scan originating from source: internal server - destination: empty</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255712#M50050</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We are currently running R81.20 Hotfix Take 105.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The IPS protection flagged a Sweep Scan originating from an internal server, with the destination showing as "null" and the service listed as HTTP_proxy (TCP/8080).&lt;/P&gt;&lt;P&gt;After 9 seconds, the system automatically applied a SAM rule to drop the connection. This action inadvertently disrupted legitimate communication with another internal server.&lt;/P&gt;&lt;P&gt;Once we identified the cause, we removed the affected server from the SAM rule, and since then the issue has not reappeared.&lt;/P&gt;&lt;P&gt;Could you help us understand what might be triggering this behavior?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 07:16:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255712#M50050</guid>
      <dc:creator>RuneSeeker</dc:creator>
      <dc:date>2025-08-22T07:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Detected Sweep Scan originating from source: internal server - destination: empty</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255770#M50063</link>
      <description>&lt;P&gt;We'd likely need to set up debug and reproduce the issue to understand the root cause of it.&lt;BR /&gt;This will require TAC assistance.&lt;/P&gt;
&lt;P&gt;However, adding an exception is probably the best way to ensure this issue doesn't happen again.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 22:10:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255770#M50063</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-22T22:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Detected Sweep Scan originating from source: internal server - destination: empty</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255864#M50105</link>
      <description>&lt;P&gt;Thank you for the reply,&lt;/P&gt;&lt;P&gt;Exceptions are configured in place long time ago. This issue was once-off, unexpected incident.&amp;nbsp;&lt;BR /&gt;It's not clear how to reproduce this incident since we don't have any possible destination or what tool or process initiated that.&lt;/P&gt;&lt;P&gt;Do you have any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 08:25:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255864#M50105</guid>
      <dc:creator>RuneSeeker</dc:creator>
      <dc:date>2025-08-25T08:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Detected Sweep Scan originating from source: internal server - destination: empty</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255924#M50122</link>
      <description>&lt;P&gt;I don't believe enough information is logged to understand what happened in this case.&lt;BR /&gt;Thus, we'd likely need to reproduce it in order to properly debug it.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 18:10:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255924#M50122</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-25T18:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: Detected Sweep Scan originating from source: internal server - destination: empty</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255970#M50134</link>
      <description>&lt;P&gt;Thanks for the assistance. We will update as more information becomes available.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 09:41:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Detected-Sweep-Scan-originating-from-source-internal-server/m-p/255970#M50134</guid>
      <dc:creator>RuneSeeker</dc:creator>
      <dc:date>2025-08-26T09:41:42Z</dc:date>
    </item>
  </channel>
</rss>

