- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
We have been getting LOT of alerts from our SIEM about Checkpoint IPS/Anti-Bot considering fastly.net domain as malicious and preventing it! We initially quarantined 200 assets before we could find in forensics that the Resource is fastly.net. Which is a false positive! Checkpoint support confirmed this too. Wondering how many pissed off today with these alerts?
This false positive for fastly.net hit us too. Glad to hear Checkpoint Support actually confirmed this was indeed a false positive. Had some angry end-users here.
We were seeing similar today. Thanks for confirming with support.
Thanks for sharing.
Andy
False positives should always be reported to TAC, which it appears a few people did in this case.
Rather than having to go thru submitting a case, maybe we could have a community share page where we can check in TO SPEED UP THE PROCESS and get the word out. This is great as it is though. I certainly had major heat yesterday for this. Is it safe to turn DNS trap back on?
Good idea.
Our alerts stopped around 6PM EST yesterday.
Reporting the issue in the community as was done in this and other similar cases helps get the word out.
Unfortunately, we do not have a more formal place to track this short of individual SK articles for specific "false positive" events.
The TAC case is to ensure the problem is properly tracked and resolved.
Is this something that Check Point would typically send a notification out to customers? If so, how do I get on that mailing list?
I went to look into the same issue yesterday, but otx.alienvault.com was getting blocked as Glupteba.TC.804cfguz 😞
I just literally realized it was same issue I dealt with the client yesterday when you said the name Glupteba. Glad to know it was known issue, but yes, raised false amarms.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 28 | |
| 12 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Tue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY