<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Blade is preventing but not enabled in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPS-Blade-is-preventing-but-not-enabled/m-p/53937#M10779</link>
    <description>If you've disabled the blades in the General Properties of the relevant gateway object, then the blades should not be active irrespective of the Threat Prevention profile assigned.&lt;BR /&gt;For any of these changes to take effect, the policy must be pushed to the relevant gateway.&lt;BR /&gt;For R80.x gateways, you can push just the Threat Prevention profile.&lt;BR /&gt;For R77.x gateways with IPS, you also need to push the Access Control policy.</description>
    <pubDate>Mon, 20 May 2019 20:49:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-05-20T20:49:45Z</dc:date>
    <item>
      <title>IPS Blade is preventing but not enabled</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-Blade-is-preventing-but-not-enabled/m-p/53932#M10776</link>
      <description>&lt;P&gt;I enabled Threat Prevention Blade and later disabled all Threat Prevention Blades from Policies and Layers and General properties of the Firewall but could see IPS&amp;nbsp; and AB traffic in the logs which is DETECT and PREVENT. In SSH , "enabled_blades" it doesn't show the Threat Prevention Blades. The logs shows the OPTIMIZED profile is being blocked but there is no Threat Prevention in the policies. When i click OPTIMIZE profile in the log it takes me to READ ONLY MODE where in the Threat Prevention i could see the OPTIMIZED profile is enabled with all Blades.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Closed the READ ONLY page and enabled back the THREAT PREVENTION Blade with IPS, AV, AB and&amp;nbsp; created a new profile disabling all the Blades and installed policy. Later again disabled Threat Prevention. Now am not able to see any Threat prevention Logs.&lt;/P&gt;&lt;P&gt;In the CPVIEW i could see the Threat prevention Blades enabled but not in "enabled_blades". Myself stimulated the same scenario in a VM and ended up with the same situation.&lt;/P&gt;&lt;P&gt;Kindly assist whether the IPS Blades will inspect traffic based on the Blades enabled in the General profile or profile inside the Threat prevention.&lt;/P&gt;&lt;P&gt;Firewall- R80.10&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 19:24:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-Blade-is-preventing-but-not-enabled/m-p/53932#M10776</guid>
      <dc:creator>sajin</dc:creator>
      <dc:date>2019-05-20T19:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Blade is preventing but not enabled</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-Blade-is-preventing-but-not-enabled/m-p/53937#M10779</link>
      <description>If you've disabled the blades in the General Properties of the relevant gateway object, then the blades should not be active irrespective of the Threat Prevention profile assigned.&lt;BR /&gt;For any of these changes to take effect, the policy must be pushed to the relevant gateway.&lt;BR /&gt;For R80.x gateways, you can push just the Threat Prevention profile.&lt;BR /&gt;For R77.x gateways with IPS, you also need to push the Access Control policy.</description>
      <pubDate>Mon, 20 May 2019 20:49:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-Blade-is-preventing-but-not-enabled/m-p/53937#M10779</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-20T20:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Blade is preventing but not enabled</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-Blade-is-preventing-but-not-enabled/m-p/53939#M10781</link>
      <description>&lt;P&gt;What is being enforced is probably the "Inspection Settings" part of the Access Control policy on your R80.10 gateway.&amp;nbsp; These will be enforced separate from any part of Threat Prevention, have you checked there?&amp;nbsp; Inspection Settings used to part of IPS in R77.30 which can be a bit confusing...&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 22:23:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-Blade-is-preventing-but-not-enabled/m-p/53939#M10781</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-05-20T22:23:08Z</dc:date>
    </item>
  </channel>
</rss>

