<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IoT Security Alerts in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/220477#M11025</link>
    <description>&lt;P&gt;Hi Dafna,&lt;BR /&gt;&lt;BR /&gt;thanks for your reply. Because of security reasons we cannot provide direct access to the device.&lt;BR /&gt;Would you be able to provide necessary trouble shooting ste&lt;FONT size="3"&gt;ps, which we can perform on our own, to figure out what is going wrong?&lt;BR /&gt;&lt;BR /&gt;We have also noticed another problem: We have 10 devices listed under the same IoT group. The group shows as policy: "Prevent". However the top panel under "Access Policy&amp;gt;IoT" shows 5 of these devices as "Unproteceted Assets". Do you have an idea what might be the problem there?&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Gabriel Pescia&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2024 08:15:40 GMT</pubDate>
    <dc:creator>zkg</dc:creator>
    <dc:date>2024-07-12T08:15:40Z</dc:date>
    <item>
      <title>IoT Security Alerts</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/219968#M11001</link>
      <description>&lt;P&gt;Dear all,&lt;BR /&gt;&lt;BR /&gt;We use a locally managed Quantum Spark 1800 appliance R81.10.10 (996002945). The appliance allows to monitor IoT devices. However this monitoring seems to be faulty.&lt;/P&gt;&lt;P&gt;For example:&lt;BR /&gt;We have (among others) two HP computers which are listed as such under Monitoring&amp;gt;Assets. In particular they are not listed under IoT assets. However, if one of these computers connects to the other, we obtain a "Security Alert" that reads "Unauthorized domain IoT access". Since neither of the two computers are listed under IoT assets the above alert makes no sense to us.&lt;/P&gt;&lt;P&gt;With this post we wanted to inquire other users if they have seen the same behaviour as described above and how to fix the issue?&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Gabriel Pescia&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 15:26:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/219968#M11001</guid>
      <dc:creator>zkg</dc:creator>
      <dc:date>2024-07-08T15:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: IoT Security Alerts</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/220015#M11007</link>
      <description>&lt;P&gt;I assume you can configure an override to resolve the issue: &lt;A href="https://support.checkpoint.com/results/sk/sk181988" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181988&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 19:49:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/220015#M11007</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-08T19:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: IoT Security Alerts</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/220036#M11008</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm Dafna working as a team leader at&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Quantum Spark&amp;nbsp;R&amp;amp;D.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;You are right - this is no the expected behavior,&lt;/P&gt;
&lt;P&gt;Is it possible to access your GW via reach my device or remote session to check it?&lt;/P&gt;
&lt;P&gt;I'm Dafna, a team leader at Quantum Spark R&amp;amp;D.&lt;/P&gt;
&lt;P&gt;You are right; this behavior is not what we would expect.&lt;/P&gt;
&lt;P&gt;Would it be possible to access your GW via "Reach My Device" or a remote session to check it?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Dafna&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 05:41:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/220036#M11008</guid>
      <dc:creator>Dafna</dc:creator>
      <dc:date>2024-07-09T05:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: IoT Security Alerts</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/220477#M11025</link>
      <description>&lt;P&gt;Hi Dafna,&lt;BR /&gt;&lt;BR /&gt;thanks for your reply. Because of security reasons we cannot provide direct access to the device.&lt;BR /&gt;Would you be able to provide necessary trouble shooting ste&lt;FONT size="3"&gt;ps, which we can perform on our own, to figure out what is going wrong?&lt;BR /&gt;&lt;BR /&gt;We have also noticed another problem: We have 10 devices listed under the same IoT group. The group shows as policy: "Prevent". However the top panel under "Access Policy&amp;gt;IoT" shows 5 of these devices as "Unproteceted Assets". Do you have an idea what might be the problem there?&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Gabriel Pescia&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 08:15:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/220477#M11025</guid>
      <dc:creator>zkg</dc:creator>
      <dc:date>2024-07-12T08:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: IoT Security Alerts</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/220661#M11035</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please provide the following information:&lt;/P&gt;
&lt;P&gt;Issue #1:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;cpinfo&lt;/LI&gt;
&lt;LI&gt;screen shot of the relevant security logs which are relevent to the HP computers&lt;/LI&gt;
&lt;LI&gt;The last notification which you got on those computers&lt;/LI&gt;
&lt;LI&gt;screen shot of your outgoing policy&lt;/LI&gt;
&lt;LI&gt;output of the following commands:
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;pt fwGeneratedRule&lt;/LI&gt;
&lt;LI&gt;fw tab -t iot_cleanup_rule_num_table&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Issue #2:&lt;/P&gt;
&lt;P&gt;1. send the device type and vendor&lt;/P&gt;
&lt;P&gt;2. screen shot of the IOT page and asset page (I want to see hoe those devices are displayed)&lt;/P&gt;
&lt;P&gt;3. the MAC address of the problematic devices&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Dafna&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2024 06:01:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IoT-Security-Alerts/m-p/220661#M11035</guid>
      <dc:creator>Dafna</dc:creator>
      <dc:date>2024-07-14T06:01:24Z</dc:date>
    </item>
  </channel>
</rss>

