<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding ThreatPrevetion exceptions by setting action to PREVENT to eliminate possibility of False in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Adding-ThreatPrevetion-exceptions-by-setting-action-to-PREVENT/m-p/109610#M20791</link>
    <description>&lt;P&gt;I think for the DNS Query, if you configure DNS Trap, it will show "Detect" instead of "Prevent". So seeing "detect" for those might be normal, depend on your setting.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Feb 2021 21:46:46 GMT</pubDate>
    <dc:creator>Cyber_Serge</dc:creator>
    <dc:date>2021-02-02T21:46:46Z</dc:date>
    <item>
      <title>Adding ThreatPrevetion exceptions by setting action to PREVENT to eliminate possibility of FalseNegs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-ThreatPrevetion-exceptions-by-setting-action-to-PREVENT/m-p/109594#M20786</link>
      <description>&lt;P&gt;Hello All,&lt;BR /&gt;&lt;BR /&gt;I have a question regarding addition of exceptions to a Threat Prevention policy on perimeter gateways.&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;BackGround&lt;/STRONG&gt;&lt;/U&gt;:&lt;BR /&gt;Few servers are running DNS queries to external honeypot site and not all of them are getting prevented by Anti-Bot, Few logs show "Detect" too.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would like to write an exception on TP policy and set the action to "Prevent", I want to try it to eliminate the possibility of any false negatives. (Refer to the attached image for the exception rule that I wanted to try)&lt;BR /&gt;&lt;BR /&gt;My question is : Is it normal to write TP exceptions and set action to prevent ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 19:49:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-ThreatPrevetion-exceptions-by-setting-action-to-PREVENT/m-p/109594#M20786</guid>
      <dc:creator>Tiger_QAs</dc:creator>
      <dc:date>2021-02-02T19:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ThreatPrevetion exceptions by setting action to PREVENT to eliminate possibility of False</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-ThreatPrevetion-exceptions-by-setting-action-to-PREVENT/m-p/109610#M20791</link>
      <description>&lt;P&gt;I think for the DNS Query, if you configure DNS Trap, it will show "Detect" instead of "Prevent". So seeing "detect" for those might be normal, depend on your setting.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 21:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-ThreatPrevetion-exceptions-by-setting-action-to-PREVENT/m-p/109610#M20791</guid>
      <dc:creator>Cyber_Serge</dc:creator>
      <dc:date>2021-02-02T21:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ThreatPrevetion exceptions by setting action to PREVENT to eliminate possibility of False</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-ThreatPrevetion-exceptions-by-setting-action-to-PREVENT/m-p/110967#M20939</link>
      <description>&lt;P&gt;Thanks a lot for the response&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25334"&gt;@Cyber_Serge&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 21:59:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-ThreatPrevetion-exceptions-by-setting-action-to-PREVENT/m-p/110967#M20939</guid>
      <dc:creator>Tiger_QAs</dc:creator>
      <dc:date>2021-02-16T21:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ThreatPrevetion exceptions by setting action to PREVENT to eliminate possibility of False</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Adding-ThreatPrevetion-exceptions-by-setting-action-to-PREVENT/m-p/111048#M20948</link>
      <description>&lt;P&gt;Yes, support for TP exceptions with an action of Prevent (instead of the usual Detect or Inactive) was added in R80.10.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 14:24:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Adding-ThreatPrevetion-exceptions-by-setting-action-to-PREVENT/m-p/111048#M20948</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-02-17T14:24:43Z</dc:date>
    </item>
  </channel>
</rss>

