<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Quantum Spark IPS question in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138706#M6219</link>
    <description>&lt;P&gt;Long shot but perhaps worth investigating is if you can write a Snort signature containing your regex.&lt;/P&gt;
&lt;P&gt;Once you have the Snort signature you can &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics-TPG/SNORT-Signature-Support.htm" target="_self"&gt;import it into your manager&lt;/A&gt;, assuming your gateway is centrally managed.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jan 2022 08:57:34 GMT</pubDate>
    <dc:creator>Ruan_Kotze</dc:creator>
    <dc:date>2022-01-18T08:57:34Z</dc:date>
    <item>
      <title>Quantum Spark IPS question</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138666#M6214</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I received a question from customer running a 1590 box and R80.20.20 version&lt;/P&gt;&lt;P&gt;Can IPS detect this pattern ( \$\{\s*(j|\$?\{.+?\}) } )&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the test is done:&lt;/P&gt;&lt;P&gt;1. By the request POST&lt;/P&gt;&lt;P&gt;2. In the HTTP header&lt;/P&gt;&lt;P&gt;3. In the HTTP data stream&lt;/P&gt;&lt;P&gt;Or is WAF required for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 16:48:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138666#M6214</guid>
      <dc:creator>Skywatcher</dc:creator>
      <dc:date>2022-01-17T16:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark IPS question</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138674#M6215</link>
      <description>&lt;P&gt;Looks like RegEx - why should IPS match that ?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 18:40:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138674#M6215</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-01-17T18:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark IPS question</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138686#M6216</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;. I dont think IPS can match that at all. Not sure if WAF can...maybe.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 01:46:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138686#M6216</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-01-18T01:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark IPS question</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138702#M6217</link>
      <description>&lt;P&gt;Let me see if I can have more info from the customer and see from there&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 07:38:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138702#M6217</guid>
      <dc:creator>Skywatcher</dc:creator>
      <dc:date>2022-01-18T07:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark IPS question</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138705#M6218</link>
      <description>&lt;P&gt;&lt;SPAN&gt;In the SMB&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Users &amp;amp; Objects&lt;/SPAN&gt;&lt;SPAN&gt; &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Applications &amp;amp; URLs&lt;/SPAN&gt;&lt;SPAN&gt; page you can define custom applications by Regular Expressions that match URLs - but your example will not match URLs...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 08:29:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138705#M6218</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-01-18T08:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark IPS question</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138706#M6219</link>
      <description>&lt;P&gt;Long shot but perhaps worth investigating is if you can write a Snort signature containing your regex.&lt;/P&gt;
&lt;P&gt;Once you have the Snort signature you can &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics-TPG/SNORT-Signature-Support.htm" target="_self"&gt;import it into your manager&lt;/A&gt;, assuming your gateway is centrally managed.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 08:57:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138706#M6219</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-01-18T08:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark IPS question</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138712#M6221</link>
      <description>&lt;P&gt;Thank you, I know that, but I don't think they had that in mind.&lt;/P&gt;&lt;P&gt;I have some assumptions that are on the path of what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9028"&gt;@Ruan_Kotze&lt;/a&gt; wrote, but didn't want to get ahead of myself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like I said let me see if I can get more info from the customer which may shed some light&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 09:16:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-IPS-question/m-p/138712#M6221</guid>
      <dc:creator>Skywatcher</dc:creator>
      <dc:date>2022-01-18T09:16:40Z</dc:date>
    </item>
  </channel>
</rss>

