- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello Mates!!!
I'm trying to bypass an Anti-Bot IP Reputation Prevent on a specific IP address, but no exception I configure seems to take effect. Hoping someone has seen this behavior before.
Environment: R81.20
Problem
In SmartConsole logs I see Prevent entries from blade Anti-Bot, Protection Type IP Reputation, against destination 13.107.138.10 - a Microsoft IP belonging to subnet 13.107.136.0/22, which is part of the Office 365 Services Updatable Object (verified by checking the office365.C file on the gateway).
The matched rule is IPS.TO Internet (corresponding to Threat Prevention policy).
Since this IP is in a Microsoft-published range I want to also exclude it from Anti-Bot IP Reputation enforcement.
What I tried
I configured a Global Exception below:
The log still shows Prevent. The Matched Rules tab in the log details shows only the parent rule IPS.TO Internet - no reference to the exception.
I then tried this additional configuration, with the same result (no match): Action set to Detect instead of Inactive (based on the suggestion in this thread: IPS exception not working
The policy was properly installed via Install Policy -> Threat Prevention.
My Questions
Any guidance is much appreciated. Screenshots attached.
Thank you
We are experiencing the same issue when trying to bypass Anti-Bot IP Reputation for part of a non-Microsoft website. Unfortunately, we have not been able to exclude the IP address in any way.
On our gateway, Threat Prevention is configured in Autonomous Policy mode.
Thank you.
Hello,
considering the operating logic of the Threat Prevention component, I could assume bypassing the issue by creating a new Profile, excluding the IP Reputation protection for it
(https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/...).
After that, I could create a custom rule for the affected traffic and apply the previously created profile to that rule.
Maybe it would work but I'd like to have your thoughts about this topic.
Hello, Thank you for the idea.
but in Threat Prevention, Autonomous Policy mode you cannot change the profile of the gateway.
Is the IP part of an IOC feed you have configured? Is there more information in the log card that might help here?
Hello @emmap,
no, it doesn’t appear that an IoC is involved here:
When IoC is involved, it is reported in log (Indicator Name)
Did you already try the exception option from the log card itself?
Yep, but I get the error: “Failed to add exception.”
Where would the exception be added when it is performed from the card?
OK. The reason I asked is that the IOC blocks are done in SecureXL and as such are not processed in the policy so exceptions don't match. This might be the case for the basic IP Reputation as well but I can't say for sure. Might be one for TAC to get to the bottom of.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 75 | |
| 17 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY