<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS best practice  in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13849#M99389</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi tomer,&lt;/P&gt;&lt;P&gt;any news on this document ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Dec 2017 09:47:04 GMT</pubDate>
    <dc:creator>aner_sagi</dc:creator>
    <dc:date>2017-12-04T09:47:04Z</dc:date>
    <item>
      <title>IPS best practice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13847#M99387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am interested in how people use IPS in R80.10.&amp;nbsp; In R77.30 we would go through the flagged list then set the relevant protections to detect for 7 days – we would then clear down the flags for the ones we do not set.&amp;nbsp; We would then review the logs to make sure there is no impact to legitimate site traffic (we have a customer facing SAAS platform) then we would set the flagged detects to protect and push policy.&amp;nbsp; We would then repeat the cycle over a two week period.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In R80.10 I am thinking I would need to do the following to emulate this:-&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Set activation mode to Detect on high and medium confidence&lt;/LI&gt;&lt;LI&gt;Set Activate IPS protections according to the following additional properties and select the vendors we want.&lt;/LI&gt;&lt;LI&gt;Set newly update protections to activation detect in Staging&lt;/LI&gt;&lt;LI&gt;Download the IPS update and push policy&lt;/LI&gt;&lt;LI&gt;Review the logs filtered to staging protections after 7 days&lt;/LI&gt;&lt;LI&gt;Set any that are affecting legitimate traffic to inactive (or add an exception)&lt;/LI&gt;&lt;LI&gt;Set the rest to Prevent and push policy.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Repeat steps 4 -7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do other people do?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2017 15:29:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13847#M99387</guid>
      <dc:creator>Jon_Dyke</dc:creator>
      <dc:date>2017-11-23T15:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPS best practice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13848#M99388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, in a few days we will publish an&amp;nbsp;"IPS Best Practices in R80.10".&lt;/P&gt;&lt;P&gt;This document is a recommendation, of course any customer can do what he prefers. The document is in its final stages of review.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regardless of the Check Point document, we are always interested to hear&amp;nbsp;you guys'&amp;nbsp;processes.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2017 15:48:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13848#M99388</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2017-11-23T15:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPS best practice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13849#M99389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi tomer,&lt;/P&gt;&lt;P&gt;any news on this document ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Dec 2017 09:47:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13849#M99389</guid>
      <dc:creator>aner_sagi</dc:creator>
      <dc:date>2017-12-04T09:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPS best practice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13850#M99390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;delayed by a couple of days unfortunately.. we will update here.&lt;/P&gt;&lt;P&gt;in the meantime your thoughts on Jon's notes?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Dec 2017 10:11:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13850#M99390</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2017-12-04T10:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPS best practice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13851#M99391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any word on an update for the guide? Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jan 2018 15:42:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13851#M99391</guid>
      <dc:creator>K__P__Kennedy</dc:creator>
      <dc:date>2018-01-10T15:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPS best practice</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13852#M99392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologize for the delays, please follow this thread -&amp;nbsp;&lt;A href="https://community.checkpoint.com/message/13840-r8010-ips-best-practices-guide" target="_blank"&gt;https://community.checkpoint.com/message/13840-r8010-ips-best-practices-guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:04:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-best-practice/m-p/13852#M99392</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2019-06-21T09:04:13Z</dc:date>
    </item>
  </channel>
</rss>

