Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
NeilDavey
Collaborator
Jump to solution

Threat Prevention Custom Policy

Good Morning

I was looking for some views around an exception on Threat Prevention if possible to see if there would be any security concerns, pros/cons etc that people could see.

No - 1
Name - Bypass IPSec and IKE
Protection Scope - * Any
Source - * Any
Destination - * Any
Protection/Site/File/Blade - N/A
Services - IKE_NAT_TRAVERSAL (Port udp/4500) / ESP (IP Protocol 50) / AH (IP Protocol 51) / IKE (Port 500) / SKIP (IP Protocol 57) / VPN1_IPSEC_encapsulation (Port 2746)
Action - All Blades are Disabled (Threat Emulation / Threat Extraction / IPS / Anti-Bot & Advanced DNS / Anti-Virus)
Track - None

No - 2
Name - Full Inspection
Protection Scope - * Any
Source - * Any
Destination - * Any
Protection/Site/File/Blade - N/A
Services - * Any
Action - All Blades are Enabled (Threat Emulation / Threat Extraction / IPS / Anti-Bot & Advanced DNS / Anti-Virus)
Track - Log/Packet Capture/Forensics

With the above rule No - 1, I am assuming this is going to bypass all Threat Prevention Protections on the setup for any site-to-site VPN's over these services/ports.  As the "Protection Scope, Source, Destination" is set as * Any, this would include all VPN's within the company and any VPN including an external 3rd party.

I could maybe see a pro if the gateway has performance issues, you "might" want to exclude some of the above to assist with this.  But then doing this, is it a con as you are not doing any Threat Prevention scanning on these services/ports.

Maybe this would be acceptable for company to company VPN's but any VPN including a 3rd party you would not want this bypass.

For rule No - 2 , I assume that once the site-to-site VPN is established, the 2nd rule would then scan the traffic inside the VPN with all the enabled blades.

If anyone has any advice on this, that would be much appreciated.

Thanks

 

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
MVP Gold
MVP Gold

Rule 1 is a "null profile", probably for performance reasons, and is for VPN traffic transiting the firewall.  All of these protocols are encrypted, so the firewall can't inspect anything beyond the outer headers anyway, except for Phase 1 of IKE and also AH, which is almost never used by itself without ESP.  The UDP-based protocols (IKE, VPN1_IPSEC_encapsulation, IKE_NAT_TRAVERSAL) may become eligible for fastpath processing via this null profile, while the remaining non-UDP/TCP protocols will still have to go through the slowpath.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization

View solution in original post

0 Kudos
4 Replies
morris
Collaborator

When you create an exception there must be a reason for that. Whats the reason? Are you experiencing any issue if those exceptions are not active?

0 Kudos
NeilDavey
Collaborator

Thanks for the reply @morris 

Correct.  When I add an exception, there is a reason for it.  I would also try and be specific on Source/Destination/Service or Port and also a specific protection rather than bypass all.

I am actually reviewing this on behalf of a client so before I go back and ask why it was added, I was interested to get some further knowledge on this.

I have other queries around some other exceptions that have been put in place as well but wanted to get some facts etc first if that makes sense.

0 Kudos
NeilDavey
Collaborator

I assume on this, we shouldn't be adding a rule in like this as a "just in case" type scenario?

There should be some kind of business reason as to why you need to bypass these services?

Are there big security concerns with the rules as per the original comment I made would you say?

0 Kudos
Timothy_Hall
MVP Gold
MVP Gold

Rule 1 is a "null profile", probably for performance reasons, and is for VPN traffic transiting the firewall.  All of these protocols are encrypted, so the firewall can't inspect anything beyond the outer headers anyway, except for Phase 1 of IKE and also AH, which is almost never used by itself without ESP.  The UDP-based protocols (IKE, VPN1_IPSEC_encapsulation, IKE_NAT_TRAVERSAL) may become eligible for fastpath processing via this null profile, while the remaining non-UDP/TCP protocols will still have to go through the slowpath.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events