<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sweep Scan preventing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198676#M66697</link>
    <description>&lt;P&gt;If you have Smartevent, utilizing a response for external IP Sweeps to block the source IP address for a time you determine works great.&amp;nbsp; I would advise the first time you do enable the feature in Smartevent, enable a response with an email to you so you can see the volume and make sure you would not block legitimate sources.&amp;nbsp; Using Playblocks, in the portal.checkpoint.com, they have some automations for blocking that maybe what you are looking for if you do not have Smartevent. Obviously, you would need a license for Smartevent or Playblocks.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Nov 2023 15:14:56 GMT</pubDate>
    <dc:creator>JoSec</dc:creator>
    <dc:date>2023-11-22T15:14:56Z</dc:date>
    <item>
      <title>Sweep Scan preventing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198185#M66692</link>
      <description>&lt;P&gt;Hello, I have a question, currently we se sweep scan logs, we have&amp;nbsp; already configured the Host port Scan but it appears in Detect mode, it there a way to verify that it is actually blocking or is it normal that the logs show it in Detect mode and not Prevent mode ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 18:23:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198185#M66692</guid>
      <dc:creator>Elias</dc:creator>
      <dc:date>2023-11-16T18:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sweep Scan preventing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198200#M66693</link>
      <description>&lt;P&gt;The URL below, indicates the signature will only alert to the activity but not block. You can utilize Smartevent which will use SAM rules to block an IP address for configurable amount of time for IP Sweeps, port scans and other detections.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R80.30/SmartConsole_OLH/EN/jj4esSF9GWk3-Am1vs1tNQ2" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R80.30/SmartConsole_OLH/EN/jj4esSF9GWk3-Am1vs1tNQ2&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 20:05:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198200#M66693</guid>
      <dc:creator>JoSec</dc:creator>
      <dc:date>2023-11-16T20:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sweep Scan preventing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198201#M66694</link>
      <description>&lt;P&gt;Makes sense, as it does not give option to block it from IPS protection itself in smart console.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 20:48:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198201#M66694</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T20:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Sweep Scan preventing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198672#M66695</link>
      <description>&lt;P&gt;So what can I do to block this type of scanning ??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 14:59:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198672#M66695</guid>
      <dc:creator>Elias</dc:creator>
      <dc:date>2023-11-22T14:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Sweep Scan preventing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198673#M66696</link>
      <description>&lt;P&gt;Maybe better to open TAC support case to get an official answer.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 15:03:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198673#M66696</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-22T15:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sweep Scan preventing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198676#M66697</link>
      <description>&lt;P&gt;If you have Smartevent, utilizing a response for external IP Sweeps to block the source IP address for a time you determine works great.&amp;nbsp; I would advise the first time you do enable the feature in Smartevent, enable a response with an email to you so you can see the volume and make sure you would not block legitimate sources.&amp;nbsp; Using Playblocks, in the portal.checkpoint.com, they have some automations for blocking that maybe what you are looking for if you do not have Smartevent. Obviously, you would need a license for Smartevent or Playblocks.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 15:14:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198676#M66697</guid>
      <dc:creator>JoSec</dc:creator>
      <dc:date>2023-11-22T15:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Sweep Scan preventing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198707#M66698</link>
      <description>&lt;P&gt;We are examining how to add this as a new automation to Horizon Playblocks.&lt;/P&gt;
&lt;P&gt;It already includes automations to block attacks and scans such as:&lt;/P&gt;
&lt;DIV class="titleAutomation lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Block common scanner identified by IPS&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV class="titleAutomation lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="titleAutomation lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;SPAN&gt;The automation blocks scanners across the organization and is triggered by scans that are detected by IPS with very high confidence. The block can be automatic, or upon admin's approval. The notification includes information on the scan and the scanner. More parameters can be set using the automation parameters such as the block duration, whether the block is automatic or upon admins' approval, and more.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV class="titleAutomation"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;A href="https://www.checkpoint.com/horizon/playblocks/" target="_blank"&gt;https://www.checkpoint.com/horizon/playblocks/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 21:00:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sweep-Scan-preventing/m-p/198707#M66698</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-11-22T21:00:12Z</dc:date>
    </item>
  </channel>
</rss>

