<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking IP address in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34588#M58076</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please create SAM rule in firewall. It will immediately block IP. Refer SK112061 for more information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Feb 2019 12:14:14 GMT</pubDate>
    <dc:creator>Gaurav_Pandya</dc:creator>
    <dc:date>2019-02-20T12:14:14Z</dc:date>
    <item>
      <title>Blocking IP address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34587#M58075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to proceed if I want to block an ip address immediately in FW. In both GUI and CLI is this possible?. Help me to learn. Thank You.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 11:20:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34587#M58075</guid>
      <dc:creator>Erakul_Siddhart</dc:creator>
      <dc:date>2019-02-20T11:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34588#M58076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please create SAM rule in firewall. It will immediately block IP. Refer SK112061 for more information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 12:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34588#M58076</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-02-20T12:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34589#M58077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is possible via GUI and CLI. If you wan to solve this via CLI and you are running R80.20 have a look at this&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3159"&gt;R80.20 - IP blacklist in SecureXL&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;For other Versions this would apply&lt;BR /&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk67861" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk67861"&gt;Accelerated Drop Rules Feature in R75.40 and above&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to do this via GUI you can use SAM Rules. Open SmartView Monitor -&amp;gt; Launch Menu -&amp;gt; Tools -&amp;gt; Suspicious Activity Rules -&amp;gt; Add. Further Reading here&lt;BR /&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112061&amp;amp;partition=Advanced&amp;amp;product=Security" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112061&amp;amp;partition=Advanced&amp;amp;product=Security"&gt;How to create and view Suspicious Activity Monitoring (SAM) Rules&lt;BR /&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Use with caution &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 12:22:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34589#M58077</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2019-02-20T12:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34590#M58078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You Gaurav...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 12:42:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34590#M58078</guid>
      <dc:creator>Erakul_Siddhart</dc:creator>
      <dc:date>2019-02-20T12:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34591#M58079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You Benedikt for making clearly understand...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 12:43:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-address/m-p/34591#M58079</guid>
      <dc:creator>Erakul_Siddhart</dc:creator>
      <dc:date>2019-02-20T12:43:43Z</dc:date>
    </item>
  </channel>
</rss>

