- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
We have been getting LOT of alerts from our SIEM about Checkpoint IPS/Anti-Bot considering fastly.net domain as malicious and preventing it! We initially quarantined 200 assets before we could find in forensics that the Resource is fastly.net. Which is a false positive! Checkpoint support confirmed this too. Wondering how many pissed off today with these alerts?
This false positive for fastly.net hit us too. Glad to hear Checkpoint Support actually confirmed this was indeed a false positive. Had some angry end-users here.
We were seeing similar today. Thanks for confirming with support.
Thanks for sharing.
Andy
False positives should always be reported to TAC, which it appears a few people did in this case.
Rather than having to go thru submitting a case, maybe we could have a community share page where we can check in TO SPEED UP THE PROCESS and get the word out. This is great as it is though. I certainly had major heat yesterday for this. Is it safe to turn DNS trap back on?
Good idea.
Our alerts stopped around 6PM EST yesterday.
Reporting the issue in the community as was done in this and other similar cases helps get the word out.
Unfortunately, we do not have a more formal place to track this short of individual SK articles for specific "false positive" events.
The TAC case is to ensure the problem is properly tracked and resolved.
Is this something that Check Point would typically send a notification out to customers? If so, how do I get on that mailing list?
I went to look into the same issue yesterday, but otx.alienvault.com was getting blocked as Glupteba.TC.804cfguz 😞
I just literally realized it was same issue I dealt with the client yesterday when you said the name Glupteba. Glad to know it was known issue, but yes, raised false amarms.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 13 | |
| 11 | |
| 10 | |
| 7 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 6 |
Wed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY