<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gateway properties - IPS - Does changing this setting take precedence over everything IPS relate in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127103#M56017</link>
    <description>&lt;P&gt;It uses the configuration as follows: inactive is still inactive, detect stays detect (and is no good anyway, as it costs the same resources as prevent, but without much gain), and prevent gets changed to detect.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Aug 2021 15:00:05 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2021-08-16T15:00:05Z</dc:date>
    <item>
      <title>Gateway properties - IPS - Does changing this setting take precedence over everything IPS related?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127095#M56014</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Gateway Cluster Properties page: The IPS tab--&amp;gt; Activation Mode --&amp;gt; According to Threat Prevention policy or Detect only modes.&lt;/P&gt;&lt;P&gt;Does this setting take precedence to all the IPS configuration (inactive, detect, prevent) of signatures? Where is this setting described in the R80.30 Documentation?&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 14:31:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127095#M56014</guid>
      <dc:creator>supruzer1</dc:creator>
      <dc:date>2021-08-16T14:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway properties - IPS - Does changing this setting take precedence over everything IPS relate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127099#M56015</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;you can find the information here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ThreatPrevention_AdminGuide/html_frameset.htm" target="_blank"&gt;Threat Prevention R80.30 Administration Guide (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It actually only mentiones Anti-Bot and Anti-Virus but it's the same with IPS. When choosing "Detect Only" nothing is blocked but only logged and according to policy is obviously blocking traffic if you have configured it properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 14:49:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127099#M56015</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-08-16T14:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway properties - IPS - Does changing this setting take precedence over everything IPS relate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127101#M56016</link>
      <description>&lt;P&gt;Yes that's the issue&amp;gt; I can't find any related info on the IPS settings. There are many settings on that page also&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 14:57:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127101#M56016</guid>
      <dc:creator>supruzer1</dc:creator>
      <dc:date>2021-08-16T14:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway properties - IPS - Does changing this setting take precedence over everything IPS relate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127103#M56017</link>
      <description>&lt;P&gt;It uses the configuration as follows: inactive is still inactive, detect stays detect (and is no good anyway, as it costs the same resources as prevent, but without much gain), and prevent gets changed to detect.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 15:00:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127103#M56017</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-08-16T15:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway properties - IPS - Does changing this setting take precedence over everything IPS relate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127117#M56018</link>
      <description>&lt;P&gt;As Gunter says setting "Detect Only" temporarily causes IPS protections set to Prevent to act like Detect.&amp;nbsp; As mentioned in my IPS Immersion series this function was called "Troubleshooting Mode" in R77.30 and earlier, and may still be referred to by that name in some places.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 15:54:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127117#M56018</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-16T15:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway properties - IPS - Does changing this setting take precedence over everything IPS relate</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127119#M56019</link>
      <description>&lt;P&gt;Thank you G_W. Sounds like Threat Emulation setting to Detect does the same thing here.&amp;nbsp;&lt;BR /&gt;@ Marcel - The settings for Anti-Virus and Anti-Bot aren't on this page and I per G_W what he mentions makes sense as far as the Firewall properties settings are concerned. CP has settings everywhere for everything and not very intuitional. I would say for majority common administrators this becomes a major headache unless you have a dedicated team of pros, tons of money for TAC and a forgiving workplace.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 16:18:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Gateway-properties-IPS-Does-changing-this-setting-take/m-p/127119#M56019</guid>
      <dc:creator>supruzer1</dc:creator>
      <dc:date>2021-08-16T16:18:07Z</dc:date>
    </item>
  </channel>
</rss>

