<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS rejects encrypted mail in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-rejects-encrypted-mail/m-p/94774#M4080</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;For general awareness, as this might loose you e-mail if you're not looking at your smtp logs, if you have IPS set to &lt;EM&gt;strict&lt;/EM&gt; and you expect to receive SMTP with opportunistic encryption (STARTTLS), IPS will drop certain SMTP connections.&lt;/P&gt;&lt;P&gt;I couldn't find a knowledge base article with a few quick searches, to here are the details.&lt;/P&gt;&lt;P&gt;Tested on 790 GW with R77.20.87 build 3004.&lt;/P&gt;&lt;P&gt;The protection &lt;EM&gt;"SMTP STARTTLS Command" (smtp_starttls_enable)"&lt;/EM&gt; will be enabled on strict, or custom IPS settings that include it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="set.png" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7731iBDC4384A630478FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="set.png" alt="set.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The corresponding postfix log after setting the signature to detect, looks like the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE&gt;postfix/smtpd[25955]: Anonymous TLS connection established from XXXX[199.7.a.b]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can set the IPS signature it to &lt;EM&gt;detect and log&lt;/EM&gt; manually in case you need to correlate events.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2020 16:19:54 GMT</pubDate>
    <dc:creator>Michal_W_old</dc:creator>
    <dc:date>2020-08-20T16:19:54Z</dc:date>
    <item>
      <title>IPS rejects encrypted mail</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-rejects-encrypted-mail/m-p/94774#M4080</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;For general awareness, as this might loose you e-mail if you're not looking at your smtp logs, if you have IPS set to &lt;EM&gt;strict&lt;/EM&gt; and you expect to receive SMTP with opportunistic encryption (STARTTLS), IPS will drop certain SMTP connections.&lt;/P&gt;&lt;P&gt;I couldn't find a knowledge base article with a few quick searches, to here are the details.&lt;/P&gt;&lt;P&gt;Tested on 790 GW with R77.20.87 build 3004.&lt;/P&gt;&lt;P&gt;The protection &lt;EM&gt;"SMTP STARTTLS Command" (smtp_starttls_enable)"&lt;/EM&gt; will be enabled on strict, or custom IPS settings that include it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="set.png" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7731iBDC4384A630478FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="set.png" alt="set.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The corresponding postfix log after setting the signature to detect, looks like the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE&gt;postfix/smtpd[25955]: Anonymous TLS connection established from XXXX[199.7.a.b]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can set the IPS signature it to &lt;EM&gt;detect and log&lt;/EM&gt; manually in case you need to correlate events.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 16:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-rejects-encrypted-mail/m-p/94774#M4080</guid>
      <dc:creator>Michal_W_old</dc:creator>
      <dc:date>2020-08-20T16:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPS rejects encrypted mail</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-rejects-encrypted-mail/m-p/94827#M4093</link>
      <description>&lt;P&gt;Again a reason to not use the Strict IPS policy - in addition to not to use Strict Firewall Policy...&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 07:53:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-rejects-encrypted-mail/m-p/94827#M4093</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-08-21T07:53:08Z</dc:date>
    </item>
  </channel>
</rss>

