<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Have a query regarding smartevent in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100302#M19509</link>
    <description>&lt;P&gt;It blocks the source IP entirely for the configured time.&lt;BR /&gt;In this case, it's not the firewall policy that needs installing, it's the Event Policy on the SmartEvent server (e.g. A&lt;SPAN class="Menu_Options"&gt;ctions&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="SearchHighlight SearchHighlight3"&gt;Install&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Event&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight2"&gt;Policy).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Oct 2020 20:38:58 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-10-27T20:38:58Z</dc:date>
    <item>
      <title>Have a query regarding smartevent</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100288#M19502</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i have a doubt regarding port scans in smart event, so we have been getting a lot of port scans over the past month or so and im planning to block the activity if its the detected by our internet firewalls using smart event, now this post is what i came across-&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/IPS-Anti-Virus-Anti-Bot-Anti/How-can-I-avoid-quot-Host-Port-quot-scan/td-p/18550" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/IPS-Anti-Virus-Anti-Bot-Anti/How-can-I-avoid-quot-Host-Port-quot-scan/td-p/18550&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And according to the first reply by Vladimir he shows in his screenshot to block source ip as well including the event activity, now if i do select that option will it completely block the ip? or will it only block the scanning attempt (which im assuming the "block event activity" is responsible for)? ill also include the pic of what I'm talking about below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Inkedsmartevent_LI.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8644i454C489DE2E3C7B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Inkedsmartevent_LI.jpg" alt="Inkedsmartevent_LI.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also how do i install the policy on the firewall? i have pressed the save button on the top so im assuming it gets saved on the management server, now do i need to install on the firewall as well?&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 18:59:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100288#M19502</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2020-10-27T18:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Have a query regarding smartevent</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100302#M19509</link>
      <description>&lt;P&gt;It blocks the source IP entirely for the configured time.&lt;BR /&gt;In this case, it's not the firewall policy that needs installing, it's the Event Policy on the SmartEvent server (e.g. A&lt;SPAN class="Menu_Options"&gt;ctions&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="SearchHighlight SearchHighlight3"&gt;Install&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Event&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight2"&gt;Policy).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 20:38:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100302#M19509</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-27T20:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Have a query regarding smartevent</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100304#M19510</link>
      <description>&lt;P&gt;So i did install the policy on smartevent but shouldnt the changes be made on the firewall as well? like how will the firewall know about these changes? or am i thinking it wrong here?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 20:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100304#M19510</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2020-10-27T20:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Have a query regarding smartevent</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100308#M19511</link>
      <description>&lt;P&gt;so we got another internal sweep alert with destination port 22 which means the configuration didnt work?? what else do i need to do to make it work?i have installed access control policy and apparently that didnt do anything for the changes.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 23:02:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100308#M19511</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2020-10-27T23:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Have a query regarding smartevent</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100311#M19512</link>
      <description>&lt;P&gt;The block is done through a SAM rule, which doesn’t show in the Access Policy.&lt;BR /&gt;The CLI command fw sam with appropriate arguments should show the active SAM rules.&lt;BR /&gt;If you’re not seeing the appropriate rules getting created please engage with the TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 00:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100311#M19512</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-28T00:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Have a query regarding smartevent</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100320#M19515</link>
      <description>&lt;P&gt;so on the global exclusion rule as you can see below which was by default-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="smart.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8646i33EC00D65E911401/image-size/large?v=v2&amp;amp;px=999" role="button" title="smart.png" alt="smart.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So it is ticked and source and destination are "any" does that mean that all logs will be excluded from event processing as explained below in the image? so do i have to untick that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 02:53:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Have-a-query-regarding-smartevent/m-p/100320#M19515</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2020-10-28T02:53:58Z</dc:date>
    </item>
  </channel>
</rss>

