<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 and IPS protections in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31481#M6557</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you change your profiles after upgrade ? Check the inspection settings, with R80x some of protection moved from IPS blade to inspection section. In a pre-R80 smardashboard , inspection settings are configured as IPS protections.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Jun 2018 21:13:02 GMT</pubDate>
    <dc:creator>Huseyin_Rencber</dc:creator>
    <dc:date>2018-06-15T21:13:02Z</dc:date>
    <item>
      <title>R80.10 and IPS protections</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31479#M6555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We recently updated our management firewalls to R80.10 and since the upgrade we've noticed quite a few of IPS Protection blocks that weren't triggered in our previous gaia version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else seen or experienced this after moving to R80.10? A case was created with Checkpoint and they mentioned that Gaia upgrade to R80.10 has nothing to do with the IPS blade and therefore it isn't the cause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It just seems odd that all this is occurring after our upgrading our management firewall to R80.10. The gateways are still R77.30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 20:17:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31479#M6555</guid>
      <dc:creator>Richard_Lee</dc:creator>
      <dc:date>2018-06-14T20:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 and IPS protections</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31480#M6556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which IPS profile are you using?&lt;/P&gt;&lt;P&gt;The default profiles in R77.x (Default, Recommended) are different from the ones in R80.x (Basic, Optimized, Strict).&lt;/P&gt;&lt;P&gt;In terms of protections enabled, it's something like: Default &amp;lt; Basic &amp;lt; Optimized &amp;lt; Recommended &amp;lt; Strict (where Strict has the most protections enabled).&lt;/P&gt;&lt;P&gt;Also a number of changes were made in IPS protections:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103766" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103766"&gt;List of IPS Protections removed in R80.x&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bottom line: entirely possible more protections are active.&lt;/P&gt;&lt;P&gt;See also:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/IPS_Best_PracticeGuide/IPS_Best_PracticeGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/IPS_Best_PracticeGuide/IPS_Best_PracticeGuide/html_frameset.htm"&gt;Check Point R80.10 IPS Best Practices&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2018 14:28:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31480#M6556</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-15T14:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 and IPS protections</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31481#M6557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you change your profiles after upgrade ? Check the inspection settings, with R80x some of protection moved from IPS blade to inspection section. In a pre-R80 smardashboard , inspection settings are configured as IPS protections.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2018 21:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31481#M6557</guid>
      <dc:creator>Huseyin_Rencber</dc:creator>
      <dc:date>2018-06-15T21:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 and IPS protections</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31482#M6558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply. After reviewing our IPS protections, the profile has not changed. We run the recommended protections and I found that the same protection name "Internet Explorer FTP Response Parsing Memory Corruption MS07-016 CVE-2007-0217:on our other management firewalls are enabled as well, but we don't see the same issue in the R77.30 environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm might have to follow up with Checkpoint and find out why this is the case. Currently in the environment where we see the issue, we have the management FW at R80.10 and the gateways at R77.30. We have other Management FWs that need to get to R80.10 and I'm going to change the IPS to detect for that specific protection name prior to the upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's odd that we started seeing this issue only after the R80.10 upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 13:23:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31482#M6558</guid>
      <dc:creator>Richard_Lee</dc:creator>
      <dc:date>2018-06-20T13:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 and IPS protections</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31483#M6559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The profiles did not change. The protection causing issues is called "Internet Explorer FTP Response Parsing Memory Corruption (MS07-016) CVE-2007-0217. This same protection is enabled on our other locations and we don't see the issues over seas.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 13:38:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31483#M6559</guid>
      <dc:creator>Richard_Lee</dc:creator>
      <dc:date>2018-06-20T13:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 and IPS protections</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31484#M6560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The underlying parser is different between R77.30 and R80.10, which could account for some difference in behavior.&lt;/P&gt;&lt;P&gt;I recommend engaging with the TAC so we can troubleshoot what's going on.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 15:23:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-and-IPS-protections/m-p/31484#M6560</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-20T15:23:20Z</dc:date>
    </item>
  </channel>
</rss>

