<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Protocol Signatures in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/130100#M23672</link>
    <description>&lt;P&gt;Hi All.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Considering that Protocol Signature is a feature to provide more security and reliability to traffic inspection process, why is not enabled by default?&amp;nbsp;Shouldn't this be the opposite, enabled by default and I disable if I need?&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Valter Junior&lt;/P&gt;</description>
    <pubDate>Thu, 23 Sep 2021 18:16:21 GMT</pubDate>
    <dc:creator>valterj</dc:creator>
    <dc:date>2021-09-23T18:16:21Z</dc:date>
    <item>
      <title>Protocol Signatures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/107564#M20565</link>
      <description>&lt;P&gt;What are the Protocol Signatures doing?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="C_pro_sig_1.JPG" style="width: 746px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10187i8488F869944F85CA/image-size/large?v=v2&amp;amp;px=999" role="button" title="C_pro_sig_1.JPG" alt="C_pro_sig_1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 07:20:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/107564#M20565</guid>
      <dc:creator>Christian_Wagen</dc:creator>
      <dc:date>2021-01-12T07:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Protocol Signatures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/107565#M20566</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/22473"&gt;@Christian_Wagen&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;In R80.xx and R81, the identification of most common protocols are done using Firewall services with protocol signature.&amp;nbsp;&lt;BR /&gt;Signatures are pieces of information taken from both "Client to Server" and "Server to Client" packets that eventually identify the protocol. During the Service matching process, signatures validate that the content of the connection is truly the configured protocol. Protocol Signatures are part of the matching process.&lt;BR /&gt;&lt;BR /&gt;SecureXL packet flow:&lt;BR /&gt;After policy installation, all traffic matching the Service with Protocol Signature enabled, will use the Medium Patch of traffic flow (PXL, new name PSLXL).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;To use matching by protocol signature and services:&lt;/P&gt;
&lt;P&gt;- Add the matching service to the appropriate rule.&lt;BR /&gt;- Activate the Protocol Signature option.&lt;BR /&gt;- Enable&amp;nbsp;Application Control and/or&amp;nbsp; URL Filtering Blades&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 07:32:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/107565#M20566</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-01-12T07:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Protocol Signatures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/107573#M20570</link>
      <description>&lt;P&gt;Please look here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Management/White-Paper-Protecting-IoT-Internet-of-Things-implementations/td-p/38405" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Management/White-Paper-Protecting-IoT-Internet-of-Things-implementations/td-p/38405&lt;/A&gt;, in the paper itself.&lt;BR /&gt;&lt;BR /&gt;Protocol signature ensures the protocol is used according to RFC.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 09:00:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/107573#M20570</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-01-12T09:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Protocol Signatures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/130100#M23672</link>
      <description>&lt;P&gt;Hi All.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Considering that Protocol Signature is a feature to provide more security and reliability to traffic inspection process, why is not enabled by default?&amp;nbsp;Shouldn't this be the opposite, enabled by default and I disable if I need?&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Valter Junior&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 18:16:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/130100#M23672</guid>
      <dc:creator>valterj</dc:creator>
      <dc:date>2021-09-23T18:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Protocol Signatures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/212789#M35201</link>
      <description>&lt;P&gt;The Protocol Signature checkbox is not enabled on any TCP or UDP services by default.&amp;nbsp; It is probably not enabled by default due to the performance hit, as it silently kills the SecureXL Accept templating rate to zero, and requires Medium Path streaming of the first few packets of the connection to determine a final match.&amp;nbsp; This is going to cause far more rulebase lookup overhead than a regular Column-based matching Firewall/Network policy rulebase lookup. With a high new connection rate the performance impact of the "Protocol Signature" feature can become quite pronounced.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 16:58:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Protocol-Signatures/m-p/212789#M35201</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-04-30T16:58:16Z</dc:date>
    </item>
  </channel>
</rss>

