<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: INSPECT code in DEF file to bypass traffic inspection?   still a &amp;quot;thing&amp;quot;?? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/INSPECT-code-in-DEF-file-to-bypass-traffic-inspection-still-a/m-p/247034#M41300</link>
    <description>&lt;P&gt;I had not seen that in some time, so dont believe it would be a "thing"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 22 Apr 2025 18:26:55 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-22T18:26:55Z</dc:date>
    <item>
      <title>INSPECT code in DEF file to bypass traffic inspection?   still a "thing"??</title>
      <link>https://community.checkpoint.com/t5/General-Topics/INSPECT-code-in-DEF-file-to-bypass-traffic-inspection-still-a/m-p/247032#M41299</link>
      <description>&lt;P&gt;Hello All --&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More than decade ago (10-15yrs), I recall a customer working with TAC to setup DEF file that effectively passed any/all inspection for gateway on specific traffic.&amp;nbsp; &amp;nbsp;In this case, the traffic of concern was backup traffic that was hammering the gateway.&amp;nbsp; &amp;nbsp; The traffic was very specific and could be granularly identified by specific src:dst/port rules.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this still a "thing"??&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively, we could create a NULL Treat Prevention policy and apply to the traffic.&amp;nbsp; &amp;nbsp;I understand from other Tim Hall comment on related post that Null TP policy is appropriate over exception.&amp;nbsp; &amp;nbsp;The latter processes all traffic and simply does not apply TP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks -GA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;reference other posts on lack of documentation on INSPECT code?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion/INSPECT-language/td-p/52145" target="_blank"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion/INSPECT-language/td-p/52145&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;also Tim Hall comment on TP exception:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Is-it-possibly-to-bypass-the-Threat-Prevention-Emulation-blade/m-p/86154/highlight/true#M13862" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Is-it-possibly-to-bypass-the-Threat-Prevention-Emulation-blade/m-p/86154/highlight/true#M13862&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 18:10:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/INSPECT-code-in-DEF-file-to-bypass-traffic-inspection-still-a/m-p/247032#M41299</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2025-04-22T18:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: INSPECT code in DEF file to bypass traffic inspection?   still a "thing"??</title>
      <link>https://community.checkpoint.com/t5/General-Topics/INSPECT-code-in-DEF-file-to-bypass-traffic-inspection-still-a/m-p/247034#M41300</link>
      <description>&lt;P&gt;I had not seen that in some time, so dont believe it would be a "thing"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 18:26:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/INSPECT-code-in-DEF-file-to-bypass-traffic-inspection-still-a/m-p/247034#M41300</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-22T18:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: INSPECT code in DEF file to bypass traffic inspection?   still a "thing"??</title>
      <link>https://community.checkpoint.com/t5/General-Topics/INSPECT-code-in-DEF-file-to-bypass-traffic-inspection-still-a/m-p/247045#M41304</link>
      <description>&lt;P&gt;Can it still be done via .def files? Quite likely.&lt;BR /&gt;However, we typically recommend using fast_accel these days, which doesn't require editing .def files (but does involve CLI commands on each gateway).&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 20:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/INSPECT-code-in-DEF-file-to-bypass-traffic-inspection-still-a/m-p/247045#M41304</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-22T20:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: INSPECT code in DEF file to bypass traffic inspection?   still a "thing"??</title>
      <link>https://community.checkpoint.com/t5/General-Topics/INSPECT-code-in-DEF-file-to-bypass-traffic-inspection-still-a/m-p/247049#M41306</link>
      <description>&lt;P&gt;Fast accel Phoneboy mentioned is definitely your answer, so I would go with that.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk156672" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk156672&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 20:55:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/INSPECT-code-in-DEF-file-to-bypass-traffic-inspection-still-a/m-p/247049#M41306</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-22T20:55:14Z</dc:date>
    </item>
  </channel>
</rss>

