- Products
- Learn
- Local User Groups
- Partners
- More
Simplify Admin Operations with R82.20
Wed, 19 August @ 5pm CET/11am EDT
The industry's first AI Network Firewall
Securing AI traffic, everywhere
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
READY OR NOT: Securing the AI Enterprise
AI Research & Threat Landscape
CheckMates Go:
No Attack Required
Check Point’s Intrusion Prevention System (IPS) is a core component of Threat Prevention, providing proactive protection against a wide range of network threats. Over time, the IPS engine and its signature formats have evolved, leading to the coexistence of "normal" and "version 2 (Ver 2)" signatures. This post explains the technical reasons for maintaining both, their architectural differences, and best practices for deployment.
IPS Architecture Overview
Check Point IPS uses a multi-layered detection engine:
IPS Inspection Flow Diagram
Traffic is processed through multiple analysis stages, with signatures applied at different protocol layers.
Normal vs. V2 Signatures: Technical Comparison
| Feature | Normal Signature | V2 Signature (INSPECTv2) |
|---|---|---|
| Detection Engine | Classic Pattern Matcher | INSPECTv2 (advanced engine) |
| Coverage | Known threats | New threats, evasive techniques, improved accuracy |
| Performance | Lower resource usage | May require more CPU/memory, but optimized for accuracy |
| Compatibility | Legacy gateways | Modern gateways (R80+) |
| Update Frequency | Less frequent | Updated regularly |
Why Maintain Both Signature Types?
Performance Considerations
Best Practices for Managing Signature Versions
Summary
References
The way to search for subscriptions without needing a special login
So if IPS Explorer is not available, what other means do we have to find out the exact pattern the IPS protection matched on?
To my knowledge, there is no way to see what a given IPS signature matches.
Hi @AlbertoThree , sorry for the delay in responding, but I found a website where we can verify the signatures and what they protect. Here are the links.
https://advisories.checkpoint.com/advisories/
https://threatwiki.checkpoint.com/threatwiki/public.htm
Thanks for the info!
You're welcome, we're here to help each other. Actually, I wrote another article on how to do this research; here's the link.
https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-Signature-Evidence-the-shor...
I think this is totally on topic, @AlbertoThree , as @Timothy_Hall said, you need a screenshot of the video to see more details. You can add them here, like in the screenshot.
Thanks @WiliRGasparetto and @WiliRGasparetto for your answers!
As soon as I am back in the office I will take a look at IPS explorer as well as review the settings.
You're welcome, count on us anytime for this and other matters.
I wrote another article related to EPS troubleshooting; it's worth reading at the link.
https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-How-to-Filter-Events-by-CVE...
Hi everyone, I found where to search for subscriptions and wrote an article about it.
https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-Signature-Evidence-the-shor...
Very nice post indeed
Thank you
From an operational perspective, how can administrators verify in SmartConsole or IPS logs whether a connection was evaluated by the classic Pattern Matcher or by INSPECTv2, and how can they objectively measure the additional detection benefit versus the performance cost of keeping both protection variants enabled?
Currently, standard SmartConsole and IPS logs do not directly indicate whether a connection was processed by the classic Pattern Matcher or by INSPECTv2. The inspection process is internal to the IPS engine, and the log shows only which protection was triggered, not the exact mechanism used.
Excellent post! Really clear and well structured.
I loved how you covered the gradual transition using Detect mode and outlined those best practices. It adds a ton of practical value for anyone managing IPS on a daily basis. Thanks for sharing!
Thank You
Yor Welcome
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 156 | |
| 103 | |
| 15 | |
| 12 | |
| 12 | |
| 9 | |
| 8 | |
| 6 | |
| 6 | |
| 6 |
Tue 11 Aug 2026 @ 11:00 AM (EDT)
Beyond Phishing: Securing Email Against SaaS and AI-Driven ThreatsThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IATue 11 Aug 2026 @ 11:00 AM (EDT)
Beyond Phishing: Securing Email Against SaaS and AI-Driven ThreatsThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 25 Aug 2026 @ 05:00 PM (CEST)
The State of Ransomware Q2 2026: This Quarter's Trends, and Their Impact on Your DefensesThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de SeguridadAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY