<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS Add ip under Prevent in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/IPS-Add-ip-under-Prevent/m-p/136925#M4936</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have the fw under IPS protection.&lt;/P&gt;&lt;P&gt;My customer request to modify the action for a single ip.&lt;BR /&gt;For all signature put this source ip under Prevent Action so override the action defined under the IPS general rule.&lt;BR /&gt;So I created an Exception with source "host ip" Protection/site/File/blade "n-A" service "Any" Action "prevent". It's correct?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Dec 2021 14:43:33 GMT</pubDate>
    <dc:creator>charlie</dc:creator>
    <dc:date>2021-12-21T14:43:33Z</dc:date>
    <item>
      <title>IPS Add ip under Prevent</title>
      <link>https://community.checkpoint.com/t5/Endpoint/IPS-Add-ip-under-Prevent/m-p/136925#M4936</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have the fw under IPS protection.&lt;/P&gt;&lt;P&gt;My customer request to modify the action for a single ip.&lt;BR /&gt;For all signature put this source ip under Prevent Action so override the action defined under the IPS general rule.&lt;BR /&gt;So I created an Exception with source "host ip" Protection/site/File/blade "n-A" service "Any" Action "prevent". It's correct?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 14:43:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/IPS-Add-ip-under-Prevent/m-p/136925#M4936</guid>
      <dc:creator>charlie</dc:creator>
      <dc:date>2021-12-21T14:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Add ip under Prevent</title>
      <link>https://community.checkpoint.com/t5/Endpoint/IPS-Add-ip-under-Prevent/m-p/136938#M4937</link>
      <description>&lt;P&gt;By putting a Prevent in the Action field of a TP Exception as in your sample rule, the effect will be that any matched protections set for Prevent will still Prevent, and also any protections matched that are set for Detect will also now Prevent.&amp;nbsp; This exception will not apply to protections that are themselves set to "Inactive", as all an exception does is potentially change the final verdict it does not control which actual protections are enforced.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 22:12:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/IPS-Add-ip-under-Prevent/m-p/136938#M4937</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-12-21T22:12:42Z</dc:date>
    </item>
  </channel>
</rss>

