<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPAM attack containment in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182980#M30520</link>
    <description>&lt;P&gt;That sounds logical.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jun 2023 19:57:32 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-06-01T19:57:32Z</dc:date>
    <item>
      <title>SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182957#M30513</link>
      <description>&lt;P&gt;Hello, team.&lt;/P&gt;
&lt;P&gt;Currently my client's network is under attack.&lt;BR /&gt;We have an On-Premise AntiSpam, which is simply not working well, and the client is receiving "infinity" of malicious SPAM mails.&lt;/P&gt;
&lt;P&gt;As a contingency measure, we have already "detected" the countries of origin from where the attacks are coming from.&lt;/P&gt;
&lt;P&gt;Is it advisable to work with Checkpoint's "Geo Policy" feature?&lt;/P&gt;
&lt;P&gt;Or is it more advisable to "enable" the AntiSPAM blade and decide to work with Checkpoint as AntiSPAM, at least temporarily.&lt;BR /&gt;The CP AntiSPAM blade, how recommendable is it? Does this blade generate hardware resources consumption for you?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 17:41:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182957#M30513</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-01T17:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182958#M30514</link>
      <description>&lt;P&gt;Buddy, block those countries IMMEDIATELY using updatable objects. Just create a rule and add those countries as source, dst as any and action block, any service.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 17:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182958#M30514</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-01T17:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182964#M30515</link>
      <description>&lt;P&gt;I applied it.&lt;/P&gt;
&lt;P&gt;Now I am in the phase of monitoring, if indeed, it starts to block it. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The Geo Policy, is another option I could work with, right?&lt;/P&gt;
&lt;P&gt;I guess it is the "criteria" of each administrator to know which one to use for these scenarios.&lt;/P&gt;
&lt;P&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 18:20:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182964#M30515</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-01T18:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182968#M30516</link>
      <description>&lt;P&gt;Use Updatable Objects of the relevant Geographies in your Access Policy if that's the approach you want to take (versus legacy Geo Policy).&amp;nbsp;&lt;BR /&gt;Should you enable Anti Spam, you may need to enable &lt;A href="https://support.checkpoint.com/results/sk/sk109699" target="_self"&gt;MTA mode&lt;/A&gt;&amp;nbsp;on the gateway unless your SMTP server doesn't require TLS.&lt;BR /&gt;Given the SK recommends using different gateways for Threat Prevention and Anti-Spam when using MTA, it's safe to say this will have a performance impact.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 18:35:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182968#M30516</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-01T18:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182969#M30517</link>
      <description>&lt;P&gt;Hey bro, as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;said, use updatable objects, as per CP documentation, it should be used for any version above R80.20&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 18:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182969#M30517</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-01T18:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182974#M30518</link>
      <description>&lt;P&gt;What I understand from the comment, is that, to use the Checkpoint AntiSPAM blade, it is recommended to use it in a Firewall that is only dedicated to "work" as if it were an On-Premise AntiSPAM, right?&lt;/P&gt;
&lt;P&gt;For the reasons that you have already exposed previously.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 19:28:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182974#M30518</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-01T19:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182976#M30519</link>
      <description>&lt;P&gt;That's the way I read that SK.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 19:34:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182976#M30519</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-01T19:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182980#M30520</link>
      <description>&lt;P&gt;That sounds logical.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 19:57:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182980#M30520</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-01T19:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182981#M30521</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;you can use the AntiSpam blade with only IP reputation feature enabled, this blocks all known malicious IP addresses sending mails. This is like using known Blacklists to block known bad SMTP servers. No TLS decryption needed for this and this has only minimal performance impacts. You can use all other features of AntiSpam blade without significant performance impact. Only &amp;nbsp;if you use ThreatPrevention and the MTA this will have an performance impact but it depends on your mail traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 20:09:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182981#M30521</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-06-01T20:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182984#M30522</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Thank you for your reply.&lt;BR /&gt;A curiosity for ignorance, the MTA is some "option" that must be enabled, as the "AntiSPAM" blade is enabled?&lt;/P&gt;
&lt;P&gt;I'm looking for it in my console, and I can't find it.&lt;/P&gt;
&lt;P&gt;I think that applying your recommendation, for now is the most viable, always avoiding that the performance of the boxes may be affected.&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 20:33:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182984#M30522</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-01T20:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182985#M30523</link>
      <description>&lt;P&gt;No, there is no need to enable MTA, except you want to decrypt SMTP TLS or using ThreatExtraction/Emulation. AntiSpam is configured via old SmartDashboard see&amp;nbsp;&lt;A title="Using Anti-Spam and Mail" href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ThreatPrevention_AdminGuide/Topics-TPG/Using_Anti_Spam_and_Mail.htm" target="_blank" rel="noopener"&gt;Using Anti-Spam and Mail&lt;/A&gt;&amp;nbsp;„Configuring an IP Reputation Policy“&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Dark_Header_and_Pattern" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Dark_Header_and_Pattern-Body-White_Background"&gt;
&lt;TD class="TableStyle-TP_Table_Dark_Header_and_Pattern-BodyD-Column_Style-White_Background"&gt;
&lt;P&gt;In &lt;SPAN class="mc-variable Vars_Other.tp_con variable"&gt;SmartConsole&lt;/SPAN&gt;, select &lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_Other.tp_set variable"&gt;Manage &amp;amp; Settings&lt;/SPAN&gt; &amp;gt; Blades &amp;gt; &lt;SPAN class="mc-variable Vars_BladesFeatures.tp_aspam variable"&gt;Anti-Spam&lt;/SPAN&gt; &amp;amp; Mail&lt;/SPAN&gt; &amp;gt; and click &lt;SPAN class="Menu_Options"&gt;Configure in &lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;SmartDashboard&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;SmartDashboard&lt;/SPAN&gt; opens and shows the &lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_aspam variable"&gt;Anti-Spam&lt;/SPAN&gt; &amp;amp; Mail&lt;/SPAN&gt; tab.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 01 Jun 2023 20:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182985#M30523</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-06-01T20:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: SPAM attack containment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182988#M30524</link>
      <description>&lt;P&gt;Just do what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;said&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21230i51E303FF801BDEB3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21231i0C886B7C6C9956DB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 20:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SPAM-attack-containment/m-p/182988#M30524</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-01T20:47:31Z</dc:date>
    </item>
  </channel>
</rss>

