<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Prevention in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269898#M45331</link>
    <description>&lt;P&gt;Thanks to everyone for the feedback, I'll try to make the rule using a different logic.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Feb 2026 13:11:01 GMT</pubDate>
    <dc:creator>Aleksey135563</dc:creator>
    <dc:date>2026-02-06T13:11:01Z</dc:date>
    <item>
      <title>Threat Prevention</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269862#M45320</link>
      <description>&lt;P&gt;   &lt;/P&gt;&lt;P&gt;Could you please tell me why the exclusion rule in the Threat Prevention policy might not be triggered? We configured an exclusion rule for Threat Emulation at the IP address src:10.216.5.184 dst:146.75.119.52 (for the resource download.postgresql.org), but judging by the ITU logs, the rule isn't triggered and traffic is being routed to emulation. Traffic to emulation is routed to the following devices in the screenshot.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001 (4).png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33072i971514323C6FFFE0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image001 (4).png" alt="image001 (4).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image002 (3).png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33071i8F04E883D1C29CD4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image002 (3).png" alt="image002 (3).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001 (4).png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33070i9C693B811D5E134D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image001 (4).png" alt="image001 (4).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image003 (1).png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33069iA9694DE5B22C633B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image003 (1).png" alt="image003 (1).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 08:41:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269862#M45320</guid>
      <dc:creator>Aleksey135563</dc:creator>
      <dc:date>2026-02-06T08:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269879#M45323</link>
      <description>&lt;P&gt;I cannot determine from the screenshots whether the connection matched the exception rule. You can try clicking the "Add Exception" button in the connection's detailed log or consider creating a Global Exception rule.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 09:10:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269879#M45323</guid>
      <dc:creator>tankp</dc:creator>
      <dc:date>2026-02-06T09:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269883#M45325</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Aleksey135563_0-1770378562549.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33081i79E2DFBCB312F3AA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Aleksey135563_0-1770378562549.png" alt="Aleksey135563_0-1770378562549.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 11:49:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269883#M45325</guid>
      <dc:creator>Aleksey135563</dc:creator>
      <dc:date>2026-02-06T11:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269888#M45327</link>
      <description>&lt;P&gt;I dont see the gateway listed for policy install referenced in the other screenshot you attached. Maybe thats the reason? Im referring to one called fw-internet.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 12:09:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269888#M45327</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-06T12:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269891#M45328</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Did you made a typo in the object's configuration?&lt;BR /&gt;Object name is&amp;nbsp;10.216.5.184 but is the configured IP correct?&lt;BR /&gt;&lt;BR /&gt;Have had this before and could not find out why a rule was not hit. It was a typo in the objects configuration.&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 12:36:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269891#M45328</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-02-06T12:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269897#M45330</link>
      <description>&lt;P&gt;Excellent point&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;. I had seen that happen to few people before, definitely worth checking.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 13:08:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269897#M45330</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-06T13:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269898#M45331</link>
      <description>&lt;P&gt;Thanks to everyone for the feedback, I'll try to make the rule using a different logic.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 13:11:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269898#M45331</guid>
      <dc:creator>Aleksey135563</dc:creator>
      <dc:date>2026-02-06T13:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269900#M45332</link>
      <description>&lt;P&gt;There is absolutely nothing wrong with your logic. Just make sure as Martijn said IP is correct and also policy is installed on the right gateway.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 13:12:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Threat-Prevention/m-p/269900#M45332</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-06T13:12:33Z</dc:date>
    </item>
  </channel>
</rss>

