<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Ease of Use in R80.20 TechTalk in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Ease-of-Use-in-R80-20-TechTalk/m-p/19362#M58575</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this talk we mainly discussed the changes with IPS in R80.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some links:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE class="j-table jiveBorder" style="border-width: 1px; border-color: #c6c6c6;" width="100%"&gt;&lt;TBODY&gt;&lt;TR style="background: #2e3f58; font-weight: bolder; color: #e8f1ff; height: 25px;"&gt;&lt;TD style="width: 40%; height: 25px;"&gt;&lt;STRONG&gt;Link description&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="height: 25px;"&gt;&lt;STRONG&gt;Link&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 25px;"&gt;&lt;TD style="width: 40%; height: 25px;"&gt;The R80.20 EA Program&lt;/TD&gt;&lt;TD style="height: 25px;"&gt;&lt;A href="https://community.checkpoint.com/thread/7612"&gt;Check Point R80.20 Production and Public EA&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background-color: #f6f7f9; height: 50px;"&gt;&lt;TD style="width: 40%; height: 50px;"&gt;Which policy to install when making IPS changes depending on the version of your gateway&lt;/TD&gt;&lt;TD style="height: 50px;"&gt;&lt;A href="https://community.checkpoint.com/thread/1404"&gt;What is the roadmap for Threat Prevention Policy management?&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 75px;"&gt;&lt;TD style="width: 40%; height: 75px;"&gt;&lt;P&gt;IPS Best Practices for R80.10&lt;/P&gt;&lt;P&gt;(please note that for R80.20 the best practices are changed, there are 3 major changes, as we explained in the video)&lt;/P&gt;&lt;/TD&gt;&lt;TD style="height: 75px;"&gt;&lt;A href="https://community.checkpoint.com/thread/6808"&gt;R80.10 IPS Best Practices Guide&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background-color: #f6f7f9; height: 50px;"&gt;&lt;TD style="width: 40%; height: 50px;"&gt;IPS Analyzer&amp;nbsp;measures the top consumed IPS protections on your&amp;nbsp;security gateways&lt;/TD&gt;&lt;TD style="height: 50px;"&gt;&lt;A href="https://community.checkpoint.com/thread/8218"&gt;IPS Analyzer Tool - are you running it?&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 25px;"&gt;&lt;TD style="width: 40%; height: 25px;"&gt;Add custom IPS Protections based on Snort&lt;/TD&gt;&lt;TD style="height: 25px;"&gt;&lt;A href="https://community.checkpoint.com/thread/7424"&gt;Did you know? Add Snort Protections with R80.10 API&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background-color: #f6f7f9; height: 25px;"&gt;&lt;TD style="width: 40%; height: 25px;"&gt;Automate IPS with tags&lt;/TD&gt;&lt;TD style="height: 25px;"&gt;&lt;A href="https://community.checkpoint.com/thread/5565"&gt;Automating IPS&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 50px;"&gt;&lt;TD style="width: 40%; height: 50px;"&gt;Difference between ThreatCloud protections (9100+) and Core Protections (39)&lt;/TD&gt;&lt;TD style="height: 50px;"&gt;&lt;A href="https://community.checkpoint.com/thread/5159"&gt;Where did all my IPS Protections go?&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Aug 2018 05:24:20 GMT</pubDate>
    <dc:creator>Tomer_Sole</dc:creator>
    <dc:date>2018-08-15T05:24:20Z</dc:date>
    <item>
      <title>IPS Ease of Use in R80.20 TechTalk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Ease-of-Use-in-R80-20-TechTalk/m-p/19361#M58574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;As a follow-up to our&amp;nbsp;&lt;/SPAN&gt;&lt;A _jive_internal="true" data-containerid="2011" data-containertype="14" data-objectid="8546" data-objecttype="1" href="https://community.checkpoint.com/thread/8546-check-point-r8020-demo-techtalk" style="color: #6d6e71; background-color: #ffffff; border: 0px; padding: 1px 0px 1px calc(12px + 0.35ex);"&gt;Check Point R80.20 Demo TechTalk and Q&amp;amp;A&lt;/A&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&amp;nbsp;session,&amp;nbsp;we demonstrated the numerous usability enhancements with IPS Management and Gateway that are coming with the R80.20 release. Experts from R&amp;amp;D answered your IPS-related questions as well!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #1d2129; font-size: 14px;"&gt;&lt;A href="https://community.checkpoint.com/migrated-users/6703"&gt;Tomer Sole&lt;/A&gt;‌&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #1d2129; font-size: 14px;"&gt;&lt;A href="https://community.checkpoint.com/migrated-users/44207"&gt;Smadi Paradise&lt;/A&gt;‌&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #1d2129; font-size: 14px;"&gt;&lt;A href="https://community.checkpoint.com/migrated-users/46194"&gt;Ofir Israel&lt;/A&gt;‌&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #1d2129; font-size: 14px;"&gt;&lt;A href="https://community.checkpoint.com/migrated-users/54886"&gt;Raz Shlomo&lt;/A&gt;‌&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #1d2129; font-size: 14px;"&gt;Avishai Duer&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #1d2129; font-size: 14px;"&gt;As this was primarily a live demo, there are no slides.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #1d2129; font-size: 14px;"&gt;Video&amp;nbsp;will be available to&amp;nbsp;CheckMates members who are signed in:&amp;nbsp;&lt;A href="https://community.checkpoint.com/videos/6625"&gt;IPS Ease of Use in R80.20 Video&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #1d2129; font-size: 14px;"&gt;Links mentioned during the session are posted in the comments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #1d2129; font-size: 14px;"&gt;&lt;A href="https://community.checkpoint.com/videos/6625"&gt; Video Link : 6625 &lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2018 03:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Ease-of-Use-in-R80-20-TechTalk/m-p/19361#M58574</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-15T03:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Ease of Use in R80.20 TechTalk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Ease-of-Use-in-R80-20-TechTalk/m-p/19362#M58575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this talk we mainly discussed the changes with IPS in R80.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some links:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE class="j-table jiveBorder" style="border-width: 1px; border-color: #c6c6c6;" width="100%"&gt;&lt;TBODY&gt;&lt;TR style="background: #2e3f58; font-weight: bolder; color: #e8f1ff; height: 25px;"&gt;&lt;TD style="width: 40%; height: 25px;"&gt;&lt;STRONG&gt;Link description&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="height: 25px;"&gt;&lt;STRONG&gt;Link&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 25px;"&gt;&lt;TD style="width: 40%; height: 25px;"&gt;The R80.20 EA Program&lt;/TD&gt;&lt;TD style="height: 25px;"&gt;&lt;A href="https://community.checkpoint.com/thread/7612"&gt;Check Point R80.20 Production and Public EA&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background-color: #f6f7f9; height: 50px;"&gt;&lt;TD style="width: 40%; height: 50px;"&gt;Which policy to install when making IPS changes depending on the version of your gateway&lt;/TD&gt;&lt;TD style="height: 50px;"&gt;&lt;A href="https://community.checkpoint.com/thread/1404"&gt;What is the roadmap for Threat Prevention Policy management?&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 75px;"&gt;&lt;TD style="width: 40%; height: 75px;"&gt;&lt;P&gt;IPS Best Practices for R80.10&lt;/P&gt;&lt;P&gt;(please note that for R80.20 the best practices are changed, there are 3 major changes, as we explained in the video)&lt;/P&gt;&lt;/TD&gt;&lt;TD style="height: 75px;"&gt;&lt;A href="https://community.checkpoint.com/thread/6808"&gt;R80.10 IPS Best Practices Guide&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background-color: #f6f7f9; height: 50px;"&gt;&lt;TD style="width: 40%; height: 50px;"&gt;IPS Analyzer&amp;nbsp;measures the top consumed IPS protections on your&amp;nbsp;security gateways&lt;/TD&gt;&lt;TD style="height: 50px;"&gt;&lt;A href="https://community.checkpoint.com/thread/8218"&gt;IPS Analyzer Tool - are you running it?&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 25px;"&gt;&lt;TD style="width: 40%; height: 25px;"&gt;Add custom IPS Protections based on Snort&lt;/TD&gt;&lt;TD style="height: 25px;"&gt;&lt;A href="https://community.checkpoint.com/thread/7424"&gt;Did you know? Add Snort Protections with R80.10 API&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background-color: #f6f7f9; height: 25px;"&gt;&lt;TD style="width: 40%; height: 25px;"&gt;Automate IPS with tags&lt;/TD&gt;&lt;TD style="height: 25px;"&gt;&lt;A href="https://community.checkpoint.com/thread/5565"&gt;Automating IPS&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 50px;"&gt;&lt;TD style="width: 40%; height: 50px;"&gt;Difference between ThreatCloud protections (9100+) and Core Protections (39)&lt;/TD&gt;&lt;TD style="height: 50px;"&gt;&lt;A href="https://community.checkpoint.com/thread/5159"&gt;Where did all my IPS Protections go?&lt;/A&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2018 05:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Ease-of-Use-in-R80-20-TechTalk/m-p/19362#M58575</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-08-15T05:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Ease of Use in R80.20 TechTalk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Ease-of-Use-in-R80-20-TechTalk/m-p/19363#M58576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I realize I'm a bit late posting the Q&amp;amp;A for this, but it's still good to have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;When you do install policy, does it update only the&amp;nbsp;IPS or all the fw policy?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;On R80+ gateways, IPS is part of the Threat Prevention policy and can be pushed separately from the Firewall/Access Control policy. In R77.30 and earlier, to update IPS, you must install the Firewall policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Is there an option for customize the user credentials in order to make the IPS update ? I cannot find it in R80.10 ... In R77.30 it was easy.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;In R80.x this is no longer required as we use a certificate to authenticate access to UserCenter to download the signatures.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;And how about that offline updates?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;To receive the offline IPS signature update files, you must sign a special EULA. Please check with your local office.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;What is the purpose of the indicators tab in threat tools?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;You can block specific URLs or file hashes. This requires Anti-Virus and/or Anti-Bot to be activated and is not an IPS feature.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Any way to turn off just IPS to troubleshoot a problem? Too often troubleshooting takes too long and want a quick way to test without pushing policy.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;The cli command &lt;STRONG&gt;ips off&lt;/STRONG&gt; will disable IPS. However, this is a last resort and is not recommended.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;I remember the CSV being available in R77.20 when was STIX format added ? Does R80.20 also support TAXII format?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;STIX has been available since R77.20, TAXI is not currently supported.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;See the upcoming feature in &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193"&gt;sk132193&lt;/A&gt;, TAXII might be developed on top of it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Can we put the newly downloaded protection in inactive state just to avoid high CPU sometimes when the box is already under load?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Yes. In the profile under IPS &amp;gt; Updates you can set 'new downloaded protection' to inactive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;We are running IPS on a L2 firewall, do you plan to implement an option to assign an interface to be marked as "outside" or "inside" interface? The current IPS cannot detect if the interface is facing the internet or the inside network.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You should be able to mark the relevant physical interface as "External" in a bridge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;When we talk about policy installation improvements, should the gateway and management both need to be in R80.10?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Some policy installation improvements can be seen with R80.10 Management. The ones discussed during the TechTalk require both gateway and management to be on R80.20.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Is it possible in R80.20 filter by the client or server protection? For example I want to deactivate all server protection in one click.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;The IPS profiles are defined with tags in R80.x rather than Client or Server. Refer to&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/IPS_Best_PracticeGuide/IPS_Best_PracticeGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/IPS_Best_PracticeGuide/IPS_Best_PracticeGuide/html_frameset.htm"&gt;Check Point R80.10 IPS Best Practices&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;How much of a benefit could be expected from adding an acceleration card for Threat Prevention? Metrics?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;The acceleration cards are not available yet. Once they are, we will provide appropriate metrics.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Where are you in terms on the API 1.2 integration and IPS - could you give us a brief overview there please?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;We do have APIs for managing Indicators of Compromise via the API, but these are not strictly IPS features.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Are there realtime blacklists/blocking of known bad IP addresses?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;This is what ThreatCloud provides. If you want to subscribe to your own,&amp;nbsp;s&lt;SPAN&gt;ee the upcoming feature in&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193" style="color: #2989c5; text-decoration: underline;"&gt;sk132193&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;About policy installation, many versions ago was stated that in R80.10 only the deltas would be installed for access control policy, however, still entire policy is installed. For R80.20 this remains the same?? if yes, for which future version would be possible install only deltas for access control?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Pushing only changed rules is planned for later releases.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;If the gateways update themselves (which is great news!!!) how would you view if an update failed?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;You'll be able to see it in the Update Status view (same as AntiVirus &amp;amp; AntiBot blades)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;How does one correlate the version of the API with the version of the manager???&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;You can see what version of the API your management server supports by going to &lt;A href="https://management-ip/api_docs"&gt;https://management-ip/api_docs&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;R80 is API v1.0, R80.10 is API v1.1, and R80.20.M1 is API v1.2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;When the gateways update themselves, do they need access to &lt;A href="http://updates.checkpoint.com"&gt;updates.checkpoint.com&lt;/A&gt;?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Refer to &lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk83520" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk83520"&gt;How to verify that Security Gateway and/or Security Management Server can access Check Point servers?&lt;/A&gt;&amp;nbsp;which will be updated with the correct information once R80.20 is available.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Does the bypass IPS feature works with respect to individual core or on all the cores?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;All cores.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;In the Threat Prevention Policy there's "Protected Scope" and also "Source/Destination" fields. What is the difference between these two types? And when would you use one or the other?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;In most cases, you would use "Protected Scope." For exceptions, explicit source/destination may be useful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Would there be any changes in the protections in R80.20, compared to R80.10 ? We have seen some protections were retired with R77.30.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;No plans to deprecate IPS protections in R80.20.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Are Core Protections not the same as Inspection Settings?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Core Protections are IPS protections, Inspection Settings are actually Firewall settings.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;IPS bypass feature monitors only worker cores or also SND cores?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;All cores, worker and SND.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Are there any disadvantages of running multiple IPS profiles one Check Point cluster (such as decreased performance)?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;No, multiple profiles / Threat Prevention layers do not increase performance impact.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;What is the impact of turning on SSL inspection along with IPS, I assume some IPS protections might work better if traffic is decrypted ?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Yes, some protections will work better with SSL Inspection enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Is it possible to monitor IPS performance graphically&amp;nbsp;on SmartConsole e.g.&amp;nbsp; to match particular IPS processing time against CPU/loading,&amp;nbsp; believe this is cli only - would be a&amp;nbsp;&lt;/SPAN&gt;good feature to see in console for the future or possibly alert to any impact etc.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P&gt;Data can be collected about this, but it must currently be analyzed by TAC or R&amp;amp;D.&amp;nbsp;Instructions are available here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43733" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43733"&gt;How to measure CPU time consumed by IPS protections&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 02:45:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Ease-of-Use-in-R80-20-TechTalk/m-p/19363#M58576</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-30T02:45:08Z</dc:date>
    </item>
  </channel>
</rss>

