<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: uuid instead of ip in the mail alert in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236438#M63609</link>
    <description>&lt;P&gt;It's possible the UUID actually corresponds to an object with the same ID.&lt;BR /&gt;You can check that with mgmt_cli -r true show host uid xxxx&lt;BR /&gt;Unfortunately, I don't believe this is something you can change...confirm with TAC.&lt;/P&gt;
&lt;P&gt;Also, this statement seems contradictory:&amp;nbsp;&lt;SPAN&gt;When scanning with Zmap, IPS detects Port Scan (Host Port Scan or Sweep Scan depending on scan settings) and does not catch Zmap.&lt;BR /&gt;Can you elaborate, perhaps with a more precise example?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Dec 2024 21:09:43 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-12-19T21:09:43Z</dc:date>
    <item>
      <title>uuid instead of ip in the mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/235991#M63608</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;&lt;P&gt;A client has asked with a problem:&lt;BR /&gt;When receiving a Zmap scan email notification, the email displays uuid instead of source ip. In SmartConsole logs, the ip address is displayed correctly. For other alerts, full information including ip is also displayed. The mail notification is configured via internal_sendmail.&lt;BR /&gt;I would like to clarify why this is happening and is it possible to change this?&lt;/P&gt;&lt;P&gt;I am also unable to reproduce this problem in the test lab. When scanning with Zmap, IPS detects Port Scan (Host Port Scan or Sweep Scan depending on scan settings) and does not catch Zmap. What could this be related to?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 11:52:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/235991#M63608</guid>
      <dc:creator>gilyazovamir</dc:creator>
      <dc:date>2024-12-17T11:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: uuid instead of ip in the mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236438#M63609</link>
      <description>&lt;P&gt;It's possible the UUID actually corresponds to an object with the same ID.&lt;BR /&gt;You can check that with mgmt_cli -r true show host uid xxxx&lt;BR /&gt;Unfortunately, I don't believe this is something you can change...confirm with TAC.&lt;/P&gt;
&lt;P&gt;Also, this statement seems contradictory:&amp;nbsp;&lt;SPAN&gt;When scanning with Zmap, IPS detects Port Scan (Host Port Scan or Sweep Scan depending on scan settings) and does not catch Zmap.&lt;BR /&gt;Can you elaborate, perhaps with a more precise example?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 21:09:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236438#M63609</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-19T21:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: uuid instead of ip in the mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236769#M63610</link>
      <description>&lt;P&gt;Thank you for your reply,&lt;/P&gt;&lt;P&gt;Yes, there is indeed such an object. So that's why the uid comes in the alert?&lt;/P&gt;&lt;P&gt;Regarding the reproduction of the zmap problem. On test lab I'm scanning internal and external gateway networks from linux server with zmap. In IPS logs, Port Scan is detected but CPAI-2016-0215 (ZMap Security Scanner) is not detected. I want to understand what is needed for the gateway to detect this attack as a Zmap attack and not just a Port Scan.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 06:32:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236769#M63610</guid>
      <dc:creator>gilyazovamir</dc:creator>
      <dc:date>2024-12-24T06:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: uuid instead of ip in the mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236822#M63611</link>
      <description>&lt;P&gt;That would be the logical explanation for this behavior, yes.&lt;/P&gt;
&lt;P&gt;As for the question on detecting as Zmap, we don't release details on how our IPS signatures work.&lt;BR /&gt;Having said that, if you don't think it's being detected properly, that will need to be addressed through TAC.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 21:53:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236822#M63611</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-24T21:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: uuid instead of ip in the mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236838#M63612</link>
      <description>&lt;P&gt;So the only solution is to delete the object? Or is there some other option?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2024 06:31:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236838#M63612</guid>
      <dc:creator>gilyazovamir</dc:creator>
      <dc:date>2024-12-25T06:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: uuid instead of ip in the mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236902#M63613</link>
      <description>&lt;P&gt;As I said initially, you should check with TAC.&lt;BR /&gt;It's not behavior I've seen before and it might actually be a bug.&lt;BR /&gt;I suspect deleting the object will resolve the issue in the meantime.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2024 17:37:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/uuid-instead-of-ip-in-the-mail-alert/m-p/236902#M63613</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-26T17:37:49Z</dc:date>
    </item>
  </channel>
</rss>

