<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Prevention Rule/Profile Matching in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246786#M53772</link>
    <description>&lt;P&gt;You understand the purpose of the Threat Profiles correctly.&lt;BR /&gt;TAC may be necessary to figure out why this is protection is firing.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Apr 2025 20:29:43 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-04-17T20:29:43Z</dc:date>
    <item>
      <title>Threat Prevention Rule/Profile Matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246730#M53769</link>
      <description>&lt;P&gt;I have a custom threat policy with three rules defined for IDS purposes - no prevent. The rules have 3 different threat profiles:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;one for high performance impact and below,&lt;/LI&gt;&lt;LI&gt;one for medium performance impact and below&lt;/LI&gt;&lt;LI&gt;one for low/very low performance impact.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Each rule has a different protected scope. The high performance impact profile is at the top and the low performance impact profile is at the bottom.&lt;/P&gt;&lt;P&gt;In the logs I see the low performance impact rule detecting high performance impact protections.&lt;/P&gt;&lt;P&gt;I do not understand why. Is anyone able to advise or should I raise with TAC?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-04-17 at 08.23.55.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30260iDD5788AE8C815AF3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-04-17 at 08.23.55.png" alt="Screenshot 2025-04-17 at 08.23.55.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 07:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246730#M53769</guid>
      <dc:creator>cdav</dc:creator>
      <dc:date>2025-04-17T07:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Rule/Profile Matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246732#M53770</link>
      <description>&lt;P&gt;Better ask CP TAC for help - i can not see what you are trying to achieve and how ! If different GWs should have different IPS / TP policies, i can use a different profile for each GW. You sound as if the three profiles have the same target GW...&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 07:46:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246732#M53770</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-04-17T07:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Rule/Profile Matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246735#M53771</link>
      <description>&lt;P&gt;Maybe I have misunderstood the use of threat profiles. The intention is to have different levels of inspection based on the performance impact.&amp;nbsp;&lt;/P&gt;&lt;P&gt;E.g dev networks could have medium or below and production networks could have high or below. Each rule has a different protected scope.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 08:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246735#M53771</guid>
      <dc:creator>cdav</dc:creator>
      <dc:date>2025-04-17T08:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Rule/Profile Matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246786#M53772</link>
      <description>&lt;P&gt;You understand the purpose of the Threat Profiles correctly.&lt;BR /&gt;TAC may be necessary to figure out why this is protection is firing.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 20:29:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246786#M53772</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-17T20:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Rule/Profile Matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246793#M53773</link>
      <description>&lt;P&gt;I am fairly sure you understood how threat prevention works just right. Lots of people do it exactly that way. Personally, I would try disable ips blade, push policy, re-enable, push policy again. If that doe snot fix it, would open TAC case.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 23:18:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246793#M53773</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-17T23:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Rule/Profile Matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246797#M53774</link>
      <description>&lt;P&gt;This "Sensitive Configuration File Disclosure" protection was created very recently on 4/14/2025.&amp;nbsp; This may be a situation where the gateway automatically updated itself (if it is configured to do so), the gateway picked up this new signature in some network traffic and tried to log it, but there was a mismatch in the IPS database version between the two entities.&amp;nbsp; This can cause some rather strange logs to appear that don't always make sense.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 00:34:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246797#M53774</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-04-18T00:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Rule/Profile Matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246961#M53775</link>
      <description>&lt;P&gt;thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 06:32:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246961#M53775</guid>
      <dc:creator>cdav</dc:creator>
      <dc:date>2025-04-22T06:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Rule/Profile Matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246989#M53776</link>
      <description>&lt;P&gt;Always welcome!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 10:31:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Threat-Prevention-Rule-Profile-Matching/m-p/246989#M53776</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-22T10:31:23Z</dc:date>
    </item>
  </channel>
</rss>

