Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
s_milidrag
Contributor
Contributor

Core protection "SMTP STARTTLS Command"

Dear Check Mates,

I need some additional clarification about Core protection signature "SMTP STARTTLS Command" which is by default in Prevent mode.

Does this signature, prevent all STARTTLS over SMTP (port 25) or does it block only some irregular communication?

My network topology is very simple; SMTP gateway is behind Check Point firewall and perform NAT and access control.

Is it safe & recommended to switch this signature in DETECT mode.

 

SM
0 Kudos
1 Reply
PhoneBoy
Admin
Admin

This protection seems to trigger with some legit SMTP servers: https://support.checkpoint.com/results/sk/sk166472
In these cases, an exception should be applied.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events