<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SmartView Web -  IPS Report for a SMB Gateway in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131571#M5905</link>
    <description>&lt;P&gt;Can confirm this report filtering also works on R80.40, here is an excerpt from my new IPS/AV/ABOT Immersion video class that shows how to filter out any Threat Prevention blades not currently in use on the firewall to reduce unnecessary clutter in SmartEvent reports; not precisely the same as setting the origin but the procedure is exactly the same:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPS/AV/ABOT Immersion" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13963i1B8779F50BE37487/image-size/large?v=v2&amp;amp;px=999" role="button" title="filter1.png" alt="IPS/AV/ABOT Immersion" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;IPS/AV/ABOT Immersion&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPS/AV/ABOT Immersion" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13964iA5DE5E8CC97870BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="filter2.png" alt="IPS/AV/ABOT Immersion" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;IPS/AV/ABOT Immersion&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Oct 2021 13:47:58 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-10-12T13:47:58Z</dc:date>
    <item>
      <title>SmartView Web -  IPS Report for a SMB Gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131413#M5897</link>
      <description>&lt;P&gt;Hello Check Point Community!&lt;/P&gt;&lt;P&gt;I am working on a project with a customer that has a SMB firewall model 1570, we recently activated the IPS blade on the Gateway in detect mode.&lt;BR /&gt;We created a specific profile for this new Gateway where the idea of the profile is to be registering the most used IPS signatures to activate Prevent mode in IPS.&lt;/P&gt;&lt;P&gt;We want to make weekly reports to find some pattern and on these results, activate a customized IPS profile for the firewall.&lt;BR /&gt;I found that IPS reports can be made from SmartView Web, however, this report shows information of all the managed computers in the console.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Do you have any idea how to filter this report and only show me the IPS information of a single Gateway?&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Do you have any template or steps you can share with me?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I hope I have explained, if you have any questions, please let me know.&lt;/P&gt;&lt;P&gt;Greetings to all!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 23:45:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131413#M5897</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2021-10-08T23:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: SmartView Web -  IPS Report for a SMB Gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131415#M5898</link>
      <description>&lt;P&gt;You have to clone the report, then you can set a filter where it shows only the events from the specific gateway (specifically the origin field).&lt;/P&gt;</description>
      <pubDate>Sat, 09 Oct 2021 00:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131415#M5898</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-09T00:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: SmartView Web -  IPS Report for a SMB Gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131508#M5903</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I was clone IPS report, but when I put the filter "origin:&amp;lt;Gateway&amp;gt;", the report doesn't show results.&lt;BR /&gt;&lt;BR /&gt;Is this query placed in the top search bar or do I have to modify any section of the reports?&lt;BR /&gt;&lt;BR /&gt;Greetings&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 15:05:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131508#M5903</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2021-10-11T15:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: SmartView Web -  IPS Report for a SMB Gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131517#M5904</link>
      <description>&lt;P&gt;Seems to be working for me (Options &amp;gt; Report Filter).&lt;BR /&gt;I think the order of the filter matters since it didn't seem to work when the first item in the list was "Origin".&lt;BR /&gt;When I made it the last filter, the report returned the expected results.&lt;BR /&gt;This was on R81.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-10-11 at 11.33.40 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13958iE20A045E9B2E6E9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-10-11 at 11.33.40 AM.png" alt="Screen Shot 2021-10-11 at 11.33.40 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 18:36:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131517#M5904</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-11T18:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: SmartView Web -  IPS Report for a SMB Gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131571#M5905</link>
      <description>&lt;P&gt;Can confirm this report filtering also works on R80.40, here is an excerpt from my new IPS/AV/ABOT Immersion video class that shows how to filter out any Threat Prevention blades not currently in use on the firewall to reduce unnecessary clutter in SmartEvent reports; not precisely the same as setting the origin but the procedure is exactly the same:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPS/AV/ABOT Immersion" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13963i1B8779F50BE37487/image-size/large?v=v2&amp;amp;px=999" role="button" title="filter1.png" alt="IPS/AV/ABOT Immersion" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;IPS/AV/ABOT Immersion&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPS/AV/ABOT Immersion" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13964iA5DE5E8CC97870BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="filter2.png" alt="IPS/AV/ABOT Immersion" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;IPS/AV/ABOT Immersion&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 13:47:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131571#M5905</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-10-12T13:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: SmartView Web -  IPS Report for a SMB Gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131852#M5927</link>
      <description>&lt;P&gt;Hello, thank you for your comments.&lt;BR /&gt;I worked a case with TAC because I could not see firewall logs.&lt;BR /&gt;Currently, I can see firewall logs and other blades logs, but I cannot see any IPS logs. (I have the blade enabled and configured a profile for that SMB Firewall).&lt;/P&gt;&lt;P&gt;Does the SMB model 1570 have any limitations that prevent it from generating IPS logs?&lt;/P&gt;&lt;P&gt;Greetings!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 15:18:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SmartView-Web-IPS-Report-for-a-SMB-Gateway/m-p/131852#M5927</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2021-10-15T15:18:13Z</dc:date>
    </item>
  </channel>
</rss>

