<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some Signature show Detect even profile is set to prevent in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151477#M55331</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see 0 Bytes sent and 548 bytes received on teh log entry. I have a TAC case open for the issue.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jun 2022 13:45:25 GMT</pubDate>
    <dc:creator>Michael_Horne</dc:creator>
    <dc:date>2022-06-22T13:45:25Z</dc:date>
    <item>
      <title>Some Signature show Detect even profile is set to prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151333#M55327</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am investigating the issue of why some IPs logs are showing the action "Detected" in stead of "Prevented" as per the TP Policy. We can see from the logs that the log4js is being logged as "Detect". the log entry shows that it is matching the expected TP policy rule, using the correct TP Profile.&amp;nbsp; The TP Profile is set up to Prevent anything with Confidence level Medium that is included.&lt;/P&gt;&lt;P&gt;The one thing I notice is that the destination for the traffic is the public IP of the FW itself and that for some reason this affects the FWs ability to "Prevent" the traffic in the IPS.&lt;/P&gt;&lt;P&gt;The Logs show that the lo44js is only Detected:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16985i21E3A663BEE892F9/image-size/large?v=v2&amp;amp;px=999" role="button" title="log.png" alt="log.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The policy rule matched is set up to prevent things of medium confidence or higher:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16986i707527AD7FF1B478/image-size/large?v=v2&amp;amp;px=999" role="button" title="Policy.png" alt="Policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We can see that the log4js protections are set to "Prevent"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log4j.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16987i4A4060636C85CCE4/image-size/large?v=v2&amp;amp;px=999" role="button" title="log4j.png" alt="log4j.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Is the destination being the FWs public IP on port 80 what is causing the strange behaviour?&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 05:34:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151333#M55327</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2022-06-21T05:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Some Signature show Detect even profile is set to prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151347#M55328</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106119&amp;amp;partition=Advanced&amp;amp;product=Threat" target="_blank"&gt;sk106119: Threat Emulation blade generates a "&lt;STRONG&gt;Detect&lt;/STRONG&gt;" log instead of "&lt;STRONG&gt;Prevent&lt;/STRONG&gt;" log&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;here also listed in sk106119 are:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115252" target="_blank" rel="noopener"&gt;sk115252 - Threat Emulation logs show "Detect" for e-mail attachments instead of "Prevent" when Threat Extraction blade is also enabled&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113627" target="_blank" rel="noopener"&gt;sk113627:&amp;nbsp;Although Threat Emulation engine settings inside profile set to "Hold", Threat Emulation sends Detect Log for Malicious Files&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110625" target="_blank" rel="noopener"&gt;sk110625: Threat Emulation detects a Malicious file even if the action is set to Prevent&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 21 Jun 2022 09:00:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151347#M55328</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-06-21T09:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Some Signature show Detect even profile is set to prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151461#M55329</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;These SKs seem related to Threat Emulation, I can understand for blades that must process or analyze a file, that if the mode is set to background, then on the first instance the file is passed and the second one would be blocked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue we are facing is for IPS signature where the stream is being scanned. My understanding was that IPS signatures should be able to block the first instance.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Micahel&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 12:21:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151461#M55329</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2022-06-22T12:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: Some Signature show Detect even profile is set to prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151463#M55330</link>
      <description>&lt;P&gt;See that zero Bytes have been sent/received ? But better open a SR# with TAC to get the reason for this message !&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 12:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151463#M55330</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-06-22T12:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Some Signature show Detect even profile is set to prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151477#M55331</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see 0 Bytes sent and 548 bytes received on teh log entry. I have a TAC case open for the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 13:45:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/151477#M55331</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2022-06-22T13:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Some Signature show Detect even profile is set to prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/154986#M55332</link>
      <description>&lt;P&gt;Hi Michael,&amp;nbsp;&lt;/P&gt;&lt;P&gt;did you have any luck with this? I have same issue with AntiVirus blade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 09:12:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Some-Signature-show-Detect-even-profile-is-set-to-prevent/m-p/154986#M55332</guid>
      <dc:creator>zaoar</dc:creator>
      <dc:date>2022-08-15T09:12:41Z</dc:date>
    </item>
  </channel>
</rss>

