<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Exceptions not being applied over VPN in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200721#M9994</link>
    <description>&lt;P&gt;That was posted more than 3 years ago...&lt;/P&gt;</description>
    <pubDate>Fri, 15 Dec 2023 12:23:57 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-12-15T12:23:57Z</dc:date>
    <item>
      <title>IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93063#M3943</link>
      <description>&lt;P&gt;Hello, I've had a dig around and looked at a few post about this and none have resolved my issue.&lt;/P&gt;&lt;P&gt;We have a Locally Managed Check Point 1550 Appliance running firmware version is &lt;STRONG&gt;R80.20.05 (992001208).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Threat protection blades are enabled an up to date. When I VPN into our office and access our Twiki site from my PC over RDP we get no issues navigating around, however, if we attempt to edit any content we get an access denial, which we dont see when in the office or if I access directly from a laptop connected to the gateway over VPN .&lt;/P&gt;&lt;P&gt;--------------------------------&lt;/P&gt;&lt;P&gt;Your access is denied&lt;/P&gt;&lt;P&gt;Your access is&lt;/P&gt;&lt;P&gt;denied&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Access denied due to firewall policy violation&lt;/P&gt;&lt;P&gt;Your issue ID for support is: 5f254cd8-2-823b977f-c0000002&lt;/P&gt;&lt;P&gt;--------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have added an exception (see attached file) which has the source as our /24 subnet and have tried with destination being the single IP, the Subnet the twiki is on (Twiki is on EC2 in AWS) and to Any.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;I have even tried disabling the IPS and overridding the Command Injection IPS to be Detect vs Prevent.&amp;nbsp; Nothing changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully the Guru's here can help.&lt;/P&gt;&lt;P&gt;Regard&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 11:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93063#M3943</guid>
      <dc:creator>Steve_Parry</dc:creator>
      <dc:date>2020-08-01T11:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93065#M3944</link>
      <description>&lt;P&gt;When you say “our /24 subnet” what precisely does that refer to?&lt;BR /&gt;Can you also post the precise log card shown for the drop (redacting sensitive data)?&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 18:08:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93065#M3944</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-01T18:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93080#M3945</link>
      <description>&lt;P&gt;Thanks for the prompt reply.&lt;/P&gt;&lt;P&gt;By “our /24 subnet”&amp;nbsp; I meant the source in the rule is a Network Object that is our office subnet xxx.xxx.21.0/255.255.255.0.&lt;/P&gt;&lt;P&gt;I had thought I had attached the error.&amp;nbsp; But I have now see attached file p3.png.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2020 09:04:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93080#M3945</guid>
      <dc:creator>Steve_Parry</dc:creator>
      <dc:date>2020-08-02T09:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93089#M3946</link>
      <description>&lt;P&gt;I think there is an known issue that IPS exception rules doesn't work properly for specific pre-installed IPS protections (Command Injection/Max Ping Size etc.) until R80.20.05.&lt;BR /&gt;(For downloaded IPS signatures, exceptions rules should work)&lt;BR /&gt;&lt;BR /&gt;Can you see if the issue resolves with the latest GA firmware R80.20.10 Build 992001433? I believe the issue is fixed here.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2020 12:43:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93089#M3946</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2020-08-02T12:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93148#M3949</link>
      <description>&lt;P&gt;Thanks Tom, may be a silly question but where do I find that version? &amp;nbsp;When I check for updates on the appliance it says I am up to date. &amp;nbsp;If I click the update manually button, I am directed to a page where I can download R75 and R77 versions but no R80 ones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 10:19:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93148#M3949</guid>
      <dc:creator>Steve_Parry</dc:creator>
      <dc:date>2020-08-03T10:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93165#M3951</link>
      <description>&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;You can find the firmware download link from below.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;R80.20.10 for Small and Medium Business Appliances&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167012" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167012&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The reason why the firmware is not downloadable from the appliance WEB UI, is because the firmware is not yet available in the upgrade servers.&lt;BR /&gt;Usually new firmware is gradually deployed to the upgrade servers, after the version is widely adopted.&lt;BR /&gt;So for now, you will have to manually upgrade it with the image file available in the SK.&lt;BR /&gt;&lt;BR /&gt;Hope it helps.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 13:30:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93165#M3951</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2020-08-03T13:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93166#M3952</link>
      <description>&lt;P&gt;Thanks Tom, that makes sense. &amp;nbsp;I've downloaded that and will arrange an out of hours upgrade.&lt;/P&gt;&lt;P&gt;Thanks for all your help.&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 14:20:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/93166#M3952</guid>
      <dc:creator>Steve_Parry</dc:creator>
      <dc:date>2020-08-03T14:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/94924#M4106</link>
      <description>&lt;P&gt;Apologies for the delay, but I've not been able to get into the office until today to apply the firmware updated ( now at R80.20.10 (992001433)&lt;/P&gt;&lt;P&gt;Obviously I have missed something in the Exception setup. &amp;nbsp;From the Treat Prevention section I have added exceptions for our two subnets 192.168.21.0/24 and 192.168.25.0/24 (192.168.25.0 is our VPN/Branch subnet and 192.168.21.0/24 is the office subnet) however when I attempt to edit our Twiki page, either while on the VPN from my laptop or from an RDP session&amp;nbsp;I get the error and can see the action is prevented in the log (Screenshot 2020-08-20 at 07.31.20). &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2020-08-20 at 07.44.47.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7724iF23C18097006B8F0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2020-08-20 at 07.44.47.png" alt="Screenshot 2020-08-20 at 07.44.47.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; Any help on this would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried to send this earlier but it didnt save.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Sat, 22 Aug 2020 10:52:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/94924#M4106</guid>
      <dc:creator>Steve_Parry</dc:creator>
      <dc:date>2020-08-22T10:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200711#M9990</link>
      <description>&lt;P&gt;Hey,&lt;BR /&gt;&lt;BR /&gt;Did you find a way to bypass this problem? I have the same problem in a much recent version R81.10.05&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 10:30:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200711#M9990</guid>
      <dc:creator>pedro_filipe</dc:creator>
      <dc:date>2023-12-15T10:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200721#M9994</link>
      <description>&lt;P&gt;That was posted more than 3 years ago...&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 12:23:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200721#M9994</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-12-15T12:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200739#M10003</link>
      <description>&lt;P&gt;I will surprise you but I also have problems with CP1550 and Microsoft RDP.&lt;/P&gt;&lt;P&gt;I have people in my office who work remotely on a local Windows Server.&lt;/P&gt;&lt;P&gt;The client computers and the server are on the same subnet 192.168.1.0/24&lt;/P&gt;&lt;P&gt;When establishing an RDP connection it takes significantly longer than usual.&lt;/P&gt;&lt;P&gt;Once logged in, the session is very slow. It looks as if the server is loaded at 100%. but this is not the case. Programs do not start or start after a few minutes. Check Point CPU load at about 35-50% (ripples) RAM about 1.3 to 1.5GB (ripples).&lt;/P&gt;&lt;P&gt;Only disabling IPS, AV, SPAM module set helps. Looks like a problem with the IPS.&lt;/P&gt;&lt;P&gt;The problem occurs inside the local network + remotely via VPN.&lt;/P&gt;&lt;P&gt;Sof version: R81.10.08 (996001608)&lt;/P&gt;&lt;P&gt;The problem has been occurring for several days. Previously, everything was working. Adding servers ora computers to exceptions doesn't do anything as if it doesn't apply them.&lt;/P&gt;&lt;P&gt;I'm wondering whether to restore factory settings and configure everything from the beginning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 14:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200739#M10003</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2023-12-15T14:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200743#M10004</link>
      <description>&lt;P&gt;HeyG_W_Albrecht,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I know this post have more than 3 years, but funny enough it seems that the problem is still present in recent versions.&lt;BR /&gt;Trying to understand what can i do to bypass this problem.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 14:42:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200743#M10004</guid>
      <dc:creator>pedro_filipe</dc:creator>
      <dc:date>2023-12-15T14:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200748#M10006</link>
      <description>&lt;P&gt;Hey Lu89as,&lt;BR /&gt;&lt;BR /&gt;Just found out this is a limitation on Locally managed SMB and the VPN traffic is treated as Internal traffic...&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk177063" target="_self"&gt;SK177063&lt;/A&gt;&lt;BR /&gt;If you want o create an exception you should create one Global exception, for example in my case:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Source: Any&lt;/P&gt;&lt;P&gt;Destination: Site IP&lt;/P&gt;&lt;P&gt;Protection: Command Injection&lt;/P&gt;&lt;P&gt;Service: ANY&lt;/P&gt;&lt;P&gt;Action: Inactive&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps...&lt;BR /&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PF&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 15:55:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/200748#M10006</guid>
      <dc:creator>pedro_filipe</dc:creator>
      <dc:date>2023-12-15T15:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/238777#M11973</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;
&lt;P&gt;We are facing same issue with R81.10.10. Configured global exception but no luck.&lt;/P&gt;
&lt;P&gt;Any solution?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 12:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/238777#M11973</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2025-01-16T12:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/238798#M11976</link>
      <description>&lt;P&gt;On regular (non SMB/Spark) gateways, the protection Command Injection is a Core Protection.&amp;nbsp; To create an exception for these you don't create it on the Threat Prevention exceptions screen (those are only for IPS ThreatCloud Proections and the other 5 TP blades), you need to go to the Command Injection protection itself (or any other Core Protection) and add the exception there.&amp;nbsp; Core Protections have their own separate profile and exception mechanism, but this may be different on SMB/Spark embedded Gaia appliances.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 13:41:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/238798#M11976</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-01-16T13:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/238806#M11977</link>
      <description>&lt;P&gt;Thanks Tim for the response.&lt;/P&gt;
&lt;P&gt;There is no option to create exception in protection.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Command Injection.PNG" style="width: 541px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29232iB4255272B7077D23/image-size/large?v=v2&amp;amp;px=999" role="button" title="Command Injection.PNG" alt="Command Injection.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 13:56:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/238806#M11977</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2025-01-16T13:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Exceptions not being applied over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/239785#M12003</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;You need to put specific protection in global exception rule to make it work. I was testing with "Any" protection in exception rule.&lt;/P&gt;
&lt;P&gt;Issue is resolved after applying specific protection (Command Injection in my case) in exception rule&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 07:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/IPS-Exceptions-not-being-applied-over-VPN/m-p/239785#M12003</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2025-01-28T07:56:50Z</dc:date>
    </item>
  </channel>
</rss>

