<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAM block in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAM-block/m-p/152695#M71579</link>
    <description>&lt;P&gt;This may be a pre Infinity SOC question, but I didn't see a category for smart event.&lt;/P&gt;
&lt;P&gt;RFE, it would be nice if a SAM block told you somewhere what event in smart event triggered it.&amp;nbsp; &amp;nbsp;So, you could make an exception there instead of a global exclusion.&amp;nbsp; That being said why is my gateway using port 80 (http) to contact Akamai technologies all the time?&amp;nbsp; &amp;nbsp;What smart event protection could be the culprit here?&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;The source is actually my gateway itself, R81.10 JHF55.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Id: ac160028-44a6-3813-62cc-1f3ae3b30004&lt;BR /&gt;Marker: @A@@B@1657541940@C@1486467&lt;BR /&gt;Log Server Origin:&amp;nbsp;&lt;BR /&gt;Time: 2022-07-11T13:01:46Z&lt;BR /&gt;Interface Direction: outbound&lt;BR /&gt;Interface Name: eth17&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: true&lt;BR /&gt;Sequencenum: 83&lt;BR /&gt;Source:&amp;nbsp;&lt;BR /&gt;Source Port: 48508&lt;BR /&gt;Destination: 104.71.130.75&lt;BR /&gt;Destination Port: 80&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Message Information: SAM rule&lt;BR /&gt;Action: Reject&lt;BR /&gt;Policy Name: policy&lt;BR /&gt;Policy Management: 1&lt;BR /&gt;Db Tag: {12D898E0-1EC0-BB45-9928-AB3A4B9A15B3}&lt;BR /&gt;Policy Date: 2022-07-06T20:09:36Z&lt;BR /&gt;Blade: Firewall&lt;BR /&gt;Origin:&amp;nbsp;&lt;BR /&gt;Service: TCP/80&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 1&lt;BR /&gt;Interface: eth17&lt;BR /&gt;Type: Connection, Alert&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jul 2022 20:12:49 GMT</pubDate>
    <dc:creator>Daniel_Kavan</dc:creator>
    <dc:date>2022-07-11T20:12:49Z</dc:date>
    <item>
      <title>SAM block</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAM-block/m-p/152695#M71579</link>
      <description>&lt;P&gt;This may be a pre Infinity SOC question, but I didn't see a category for smart event.&lt;/P&gt;
&lt;P&gt;RFE, it would be nice if a SAM block told you somewhere what event in smart event triggered it.&amp;nbsp; &amp;nbsp;So, you could make an exception there instead of a global exclusion.&amp;nbsp; That being said why is my gateway using port 80 (http) to contact Akamai technologies all the time?&amp;nbsp; &amp;nbsp;What smart event protection could be the culprit here?&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;The source is actually my gateway itself, R81.10 JHF55.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Id: ac160028-44a6-3813-62cc-1f3ae3b30004&lt;BR /&gt;Marker: @A@@B@1657541940@C@1486467&lt;BR /&gt;Log Server Origin:&amp;nbsp;&lt;BR /&gt;Time: 2022-07-11T13:01:46Z&lt;BR /&gt;Interface Direction: outbound&lt;BR /&gt;Interface Name: eth17&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: true&lt;BR /&gt;Sequencenum: 83&lt;BR /&gt;Source:&amp;nbsp;&lt;BR /&gt;Source Port: 48508&lt;BR /&gt;Destination: 104.71.130.75&lt;BR /&gt;Destination Port: 80&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Message Information: SAM rule&lt;BR /&gt;Action: Reject&lt;BR /&gt;Policy Name: policy&lt;BR /&gt;Policy Management: 1&lt;BR /&gt;Db Tag: {12D898E0-1EC0-BB45-9928-AB3A4B9A15B3}&lt;BR /&gt;Policy Date: 2022-07-06T20:09:36Z&lt;BR /&gt;Blade: Firewall&lt;BR /&gt;Origin:&amp;nbsp;&lt;BR /&gt;Service: TCP/80&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 1&lt;BR /&gt;Interface: eth17&lt;BR /&gt;Type: Connection, Alert&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 20:12:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAM-block/m-p/152695#M71579</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2022-07-11T20:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: SAM block</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAM-block/m-p/152737#M71580</link>
      <description>&lt;P&gt;The Management space with a SmartEvent label would be the right classification.&lt;/P&gt;
&lt;P&gt;I suspect these reaches out to port 80 from the gateway are the gateway checking in with ThreatCloud and the like.&lt;BR /&gt;Yes, we do use Akamai as a CDN for these services.&amp;nbsp;&lt;BR /&gt;More details in sk83520.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 20:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SAM-block/m-p/152737#M71580</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-11T20:15:08Z</dc:date>
    </item>
  </channel>
</rss>

