<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW blade drops a suspicious packet like IPS blade? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/256177#M50176</link>
    <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;, and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your comments as always. Wonderful you guys are always here to help people.&lt;/P&gt;&lt;P&gt;My apologies for lack of background info. Here's why I am interested in such a good old OS version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problems:&lt;/P&gt;&lt;P&gt;No urgent issue occurs. This question was written for begging info, not a solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Backgrounds:&lt;/P&gt;&lt;P&gt;Ahead of the replacement of customer's appliances which all run R80.10, with better ones of R82,&lt;/P&gt;&lt;P&gt;I have to investigate any system change made to the system, which might cause connectivity issues.&lt;/P&gt;&lt;P&gt;Their environment has old/original protocol packets, and many of them is likely to be non RFC-compliant.&lt;/P&gt;&lt;P&gt;(I know it is almost impossible to fully presume them all, but I would like to get a picture to some extent.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I would like to know:&lt;/P&gt;&lt;P&gt;1. Without IPS blade, can FW blade drop a suspicious packets like listed in Inspection Settings?&lt;/P&gt;&lt;P&gt;2. Apart from behaviour configured in Inspection Settings, is there any function which can drop a packet regardless of firewall policy?&lt;/P&gt;&lt;P&gt;I know in global properties there are the settings associated with a drop of packets like dynamic routing protocol, direct ping, and Ack without Syn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not quite sure where else to check when policy-allowed packet is dropped at the appliance.&lt;/P&gt;&lt;P&gt;It has been very hectic in my office, so my colleagues seemingly do not have time for answering my question.. ;(&lt;/P&gt;&lt;P&gt;My effort alone cannot make them clear to me.&lt;/P&gt;&lt;P&gt;If you give me a pointer, I cannot thank you enough.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
    <pubDate>Fri, 29 Aug 2025 08:09:37 GMT</pubDate>
    <dc:creator>saitoh</dc:creator>
    <dc:date>2025-08-29T08:09:37Z</dc:date>
    <item>
      <title>FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/255972#M50135</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I heard FW blade played the role which IPS blade used to do, like dropping non-RFC compliant packet or something.&lt;/P&gt;&lt;P&gt;My experience of CP is so short that I am wondering where I can confirm what else kind/type of packet is subject to rejection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AI assistant of CheckPoint says I can find it on Manage&amp;amp;Settings &amp;gt; Blade &amp;gt; General &amp;gt; InspectionSettings, but&lt;/P&gt;&lt;P&gt;also states InspectionSettings includes 'most' of those type of packets, not all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;He or she added this behaviour of FW blade had been implemented since R80.20.&lt;/P&gt;&lt;P&gt;However R80.10 smartconsole has InspectionSettings on the same page, which I was not expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a quite confusing idea now ;(&lt;/P&gt;&lt;P&gt;It would be lovely if you share your knowledge on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 10:26:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/255972#M50135</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2025-08-26T10:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/255977#M50137</link>
      <description>&lt;P&gt;Inspection Settings &amp;amp; Core Protections fall into this category, not to worry IPS still very much exists.&lt;/P&gt;
&lt;P&gt;Both those versions are quite old how do they compare/relate to your actual installation?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 10:53:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/255977#M50137</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-08-26T10:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/255979#M50139</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/114102"&gt;@saitoh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings to a colleague in Japan! First, wanted to say, I always found Japanese culture to be the BEST and even that is an understatement.&lt;/P&gt;
&lt;P&gt;K, had to say that, because it is true. Now, as far as the issue you describe. I had some questions...first off, what is the actual issue? Do you see drops in smart console/zdebug?&lt;/P&gt;
&lt;P&gt;Also, keep in mind, when it comes to ips and inspection settings, those are totally 2 different things. Inspection settings are more related to deep packet/voip, things like that, while IPS is definitely more for protecting aginst known malicious activities.&lt;/P&gt;
&lt;P&gt;I suggest updating to at least R81.20 if you can.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 11:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/255979#M50139</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-26T11:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/255998#M50144</link>
      <description>&lt;P&gt;Several low-level packet checks are handled in the Firewall blade.&lt;BR /&gt;These are represented in the Inspection Settings and Core Protections panes and date back to the SmartDefense days (2000s pre-R70 and IPS Blade).&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 19:43:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/255998#M50144</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-26T19:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/256177#M50176</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;, and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your comments as always. Wonderful you guys are always here to help people.&lt;/P&gt;&lt;P&gt;My apologies for lack of background info. Here's why I am interested in such a good old OS version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problems:&lt;/P&gt;&lt;P&gt;No urgent issue occurs. This question was written for begging info, not a solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Backgrounds:&lt;/P&gt;&lt;P&gt;Ahead of the replacement of customer's appliances which all run R80.10, with better ones of R82,&lt;/P&gt;&lt;P&gt;I have to investigate any system change made to the system, which might cause connectivity issues.&lt;/P&gt;&lt;P&gt;Their environment has old/original protocol packets, and many of them is likely to be non RFC-compliant.&lt;/P&gt;&lt;P&gt;(I know it is almost impossible to fully presume them all, but I would like to get a picture to some extent.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I would like to know:&lt;/P&gt;&lt;P&gt;1. Without IPS blade, can FW blade drop a suspicious packets like listed in Inspection Settings?&lt;/P&gt;&lt;P&gt;2. Apart from behaviour configured in Inspection Settings, is there any function which can drop a packet regardless of firewall policy?&lt;/P&gt;&lt;P&gt;I know in global properties there are the settings associated with a drop of packets like dynamic routing protocol, direct ping, and Ack without Syn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not quite sure where else to check when policy-allowed packet is dropped at the appliance.&lt;/P&gt;&lt;P&gt;It has been very hectic in my office, so my colleagues seemingly do not have time for answering my question.. ;(&lt;/P&gt;&lt;P&gt;My effort alone cannot make them clear to me.&lt;/P&gt;&lt;P&gt;If you give me a pointer, I cannot thank you enough.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 08:09:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/256177#M50176</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2025-08-29T08:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/256180#M50178</link>
      <description>&lt;P&gt;FW can drop packets for one of those reasons:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Anti-spoofing violation&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Packet is out of state&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Policy drop rule&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Threat prevention policy decision&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 29 Aug 2025 09:36:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/256180#M50178</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-08-29T09:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/256189#M50183</link>
      <description>&lt;P&gt;Hey Saitoh,&lt;/P&gt;
&lt;P&gt;I can totally see all the points Val made, regardless of what blades are enabled.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 11:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/256189#M50183</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-29T11:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/257563#M50464</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am sorry for the late reply, had been in a short holiday in Egypt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And much appreciated to you guys for a concise and clear answer!&lt;/P&gt;&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 06:19:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/257563#M50464</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2025-09-18T06:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/257573#M50466</link>
      <description>&lt;P&gt;Glad to help&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 10:01:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/257573#M50466</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-09-18T10:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: FW blade drops a suspicious packet like IPS blade?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/257574#M50467</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/114102"&gt;@saitoh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yea man, hope you had nice Time! Egypt is very good destination, I know everyone goes to see pyramids, but I love Luxor, such a cool place.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 10:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-blade-drops-a-suspicious-packet-like-IPS-blade/m-p/257574#M50467</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-18T10:02:36Z</dc:date>
    </item>
  </channel>
</rss>

