<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Exception question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34980#M59033</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That might do it. I now have created a custom query: blade:(Anti-Bot OR IPS) NOT "Brute Force Scanning of CIFS Ports" that does basically the same, however if needed I still have the logs for other servers that may be involved in an attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I ignore logs for this signature complete, than I lose the logs that I might need for forensics.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Mar 2018 02:41:19 GMT</pubDate>
    <dc:creator>Jan_de_Gier</dc:creator>
    <dc:date>2018-03-26T02:41:19Z</dc:date>
    <item>
      <title>IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34967#M59020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently enabled IPS in detect mode to make sure that I have all false positives removed before enabling in prevent mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the false positives is coming from a monitoring system, that I want to create an exception for.&lt;/P&gt;&lt;P&gt;The monitoring system detects "Brute force scanning of CIFS ports".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to create a global exception for this:&lt;/P&gt;&lt;P&gt;Protected scope: Monitoring system IP address&lt;/P&gt;&lt;P&gt;Source: Monitoring system IP address&lt;/P&gt;&lt;P&gt;Destination: Any&lt;/P&gt;&lt;P&gt;Protection: "Brute Force scanning of CIFS ports"&lt;/P&gt;&lt;P&gt;Services" microsoft-ds (tcp/445)&lt;/P&gt;&lt;P&gt;Action: inactive&lt;/P&gt;&lt;P&gt;Track: log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering what is wrong with this global exception as I still see this protection being detected in the log files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is really appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Mar 2018 22:21:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34967#M59020</guid>
      <dc:creator>Jan_de_Gier</dc:creator>
      <dc:date>2018-03-11T22:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34968#M59021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Few questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Based on the rule you're creating, it sounds like R80.10 Management. What version on the gateway in question?&lt;/LI&gt;&lt;LI&gt;Did you push policy after making this change? (If R80.10+ Gateway, push Threat Prevention policy, for R77.30 and earlier, Access policy)&lt;/LI&gt;&lt;LI&gt;Just to clarify, are you seeing "Prevent" logs or just "Detect" logs after making changes?&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Mar 2018 23:33:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34968#M59021</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-11T23:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34969#M59022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both Mgmt and gateway are R80.10.&amp;nbsp; Policy was installed after the exception was created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS Blade is completely in detect mode at the moment. No protections are prevented.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I created a new Profile enabling IPS and AntiBot, with everything set to detect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even with the exception it is showing in the logs as detect:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Log entry" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63801_Capture.PNG" style="width: 620px; height: 354px;" /&gt;&lt;IMG alt="Threat prevention policy" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63802_Capture2.PNG" style="width: 620px; height: 69px;" /&gt;&lt;IMG alt="Global exception" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63827_Capture3.PNG" style="width: 620px; height: 56px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Mar 2018 23:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34969#M59022</guid>
      <dc:creator>Jan_de_Gier</dc:creator>
      <dc:date>2018-03-11T23:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34970#M59023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Protected Scope refers to that which an "attack" is directed.&lt;/P&gt;&lt;P&gt;Since you're wanting to create an exception just for packets from your monitoring system IP, I would set the Protected Scope to "any."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 00:20:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34970#M59023</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-12T00:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34971#M59024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah. That might be where I am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks. I'll try that and see how that goes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 01:41:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34971#M59024</guid>
      <dc:creator>Jan_de_Gier</dc:creator>
      <dc:date>2018-03-12T01:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34972#M59025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And does it work now as expected ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 11:52:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34972#M59025</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-15T11:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34973#M59026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;Günther W. Albrecht wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And does it work now as expected ?&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, I was a bit distracted from this.&lt;/P&gt;&lt;P&gt;Unfortunately not. I read this in an older document:&lt;/P&gt;&lt;H3&gt;Adding Network Exceptions&lt;/H3&gt;&lt;P&gt;You can configure exceptions for a protection with the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="padding: 0pt; color: inherit; line-height: 15px; font-weight: bold; vertical-align: baseline; display: inline; background-color: inherit;"&gt;Prevent&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;action, so that it does not identify the specified traffic. These are some situations where it is helpful to use exceptions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe exceptions don't work when the protection is set to "Detect"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody know?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 22:08:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34973#M59026</guid>
      <dc:creator>Jan_de_Gier</dc:creator>
      <dc:date>2018-03-15T22:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34974#M59027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;More on this. When I look at the logging it recognizes that the log is coming from an exception rule.&lt;/P&gt;&lt;P&gt;When I am in the details of the log and Click on the RuleID, it goes straight to the Exception rule and also when I try to create an exception out of the log details -&amp;gt; Add exception I get the error: "can't add exception rule for log generated&amp;nbsp;from exception rule"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So maybe I have to wait and see what happens if I put IPS in prevent mode and keep an eye on this specific protection. I was hoping to get all/most false positives removed before putting IPS in Prevent mode.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 22:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34974#M59027</guid>
      <dc:creator>Jan_de_Gier</dc:creator>
      <dc:date>2018-03-15T22:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34975#M59028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using the global "all protections set to detect" option or are you using a profile where the action for all signatures is set to detect?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 22:17:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34975#M59028</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-15T22:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34976#M59029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IPS activation mode on the cluster is set to "Detect Only". Besides that all protections are also set to "Detect".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Company doesn't allow me to take any risks with broken communication &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 22:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34976#M59029</guid>
      <dc:creator>Jan_de_Gier</dc:creator>
      <dc:date>2018-03-15T22:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34977#M59030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fact is that IPS protections set to detect will need much more ressources - as IPS will not stop after detect but also try to match any other IPS protection left. Set to protect, IPS will just act on the packet and do no more matching. To sum it up, detect is a good mode after deploying to get an overview but makes no sense in production.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 12:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34977#M59030</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-21T12:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34978#M59031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Gunther,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Protections will be set to Prevent eventually, we just deployed it and I want to make sure that no production is interrupted when set to detect, so I want to get all (if possible) false positives identified before I go to prevent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all the help. I think I have a reasonable idea how to attack this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 21:44:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34978#M59031</guid>
      <dc:creator>Jan_de_Gier</dc:creator>
      <dc:date>2018-03-21T21:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34979#M59032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See if you can do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64043_pastedImage_1.png" style="width: 620px; height: 313px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It won't prevent the "detection" but it will suppress the logging. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 13:24:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34979#M59032</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-23T13:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exception question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34980#M59033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That might do it. I now have created a custom query: blade:(Anti-Bot OR IPS) NOT "Brute Force Scanning of CIFS Ports" that does basically the same, however if needed I still have the logs for other servers that may be involved in an attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I ignore logs for this signature complete, than I lose the logs that I might need for forensics.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 02:41:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Exception-question/m-p/34980#M59033</guid>
      <dc:creator>Jan_de_Gier</dc:creator>
      <dc:date>2018-03-26T02:41:19Z</dc:date>
    </item>
  </channel>
</rss>

