<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SMB appliance shows Infected hosts with public IPs in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7901#M141</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is happening for a while now on my home 600 appliance:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="external IPs shown as &amp;quot;Infected Hosts&amp;quot;" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/60481_2017-10-25 19_09_21-drawbridge - Infected Hosts - Check Point 600 Appliance.png" style="width: 620px; height: 75px;" /&gt;&lt;/P&gt;&lt;P&gt;View Host Logs does not yield anything and since these events happening about once a month, running traffic capture to get better visibility into it is not practical.&lt;/P&gt;&lt;P&gt;What is the reason for this indicator being present if there is no possibility of path-through traffic hitting my gateway from inside?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Oct 2017 23:17:20 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2017-10-25T23:17:20Z</dc:date>
    <item>
      <title>SMB appliance shows Infected hosts with public IPs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7901#M141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is happening for a while now on my home 600 appliance:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="external IPs shown as &amp;quot;Infected Hosts&amp;quot;" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/60481_2017-10-25 19_09_21-drawbridge - Infected Hosts - Check Point 600 Appliance.png" style="width: 620px; height: 75px;" /&gt;&lt;/P&gt;&lt;P&gt;View Host Logs does not yield anything and since these events happening about once a month, running traffic capture to get better visibility into it is not practical.&lt;/P&gt;&lt;P&gt;What is the reason for this indicator being present if there is no possibility of path-through traffic hitting my gateway from inside?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Oct 2017 23:17:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7901#M141</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-10-25T23:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliance shows Infected hosts with public IPs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7902#M142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It could very well be a false positive of some sort, or&amp;nbsp;that IP address probing.&lt;/P&gt;&lt;P&gt;I did move this to the &lt;A href="https://community.checkpoint.com/space/2036"&gt;SMB and SMP&lt;/A&gt;‌ space.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 20:10:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7902#M142</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-27T20:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliance shows Infected hosts with public IPs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7903#M143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this was a probing attempt, I'd expect to see some drops in the log, but there is nothing at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was thinking that maybe cell phones on WiFi may ID with the IP received from the carrier, but the protection name points to Windows hosts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 20:26:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7903#M143</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-10-27T20:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliance shows Infected hosts with public IPs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7904#M144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The fact you're not seeing that is somewhat troubling.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 20:33:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7904#M144</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-27T20:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliance shows Infected hosts with public IPs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7905#M145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've re-flushed the new firmware yesterday and will keep an eye for further occurrences. Should I see it again, I may have to run continuous filtered mirroring from the switches on all interfaces to get the raw packets matching that source network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 20:47:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7905#M145</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-10-27T20:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliance shows Infected hosts with public IPs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7906#M146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Hi. &lt;BR /&gt;&lt;BR /&gt;The infected host is triggered with the Anti-Bot, which can be detected from LAN(inbound) to WAN (outgoing), and also vice versa. &lt;BR /&gt;&lt;BR /&gt;If the public&amp;nbsp;IP trying to communicate to your gateway external IP might have a malicious network activity pattern, or bad reputation (such as C&amp;amp;C), it will come up in the infected hosts list.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Oct 2017 03:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7906#M146</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2017-10-31T03:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliance shows Infected hosts with public IPs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7907#M147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no reason logging the external hosts as "Infected". Consider the scenario when your network is under attack from the botnet. In this case you may have thousands hosts listed as such. It is not the business of this device to police the Internet, but to provide you with correct information about your environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But regardless of how these two hosts ended-up listed as such, I would expect to see the corresponding log entries and there are none.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Oct 2017 13:11:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliance-shows-Infected-hosts-with-public-IPs/m-p/7907#M147</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-10-31T13:11:49Z</dc:date>
    </item>
  </channel>
</rss>

