Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ilovecheckpoint
Participant

Avoid block vulnerability scan

Hello,

We have a vulnerability scanner which scan all dmz.

On some gateways IPS has not been activated.

Firewall log show more blocked communication even if an explicit rule allow them (allows any service).

These are some of meessages seen:

ICMP type unknown 

Invalid TCP packet - source / destination port 0. Dropped although the protection is disabled

invalid content length header in request

Illegal H.225(Q.931) message

 

Is there a way to avoid to block any flow from a specific source?

0 Kudos
1 Reply
G_W_Albrecht
Legend Legend
Legend

See: sk65200: How to list all services with enabled "Match for Any" option not all services are matched by Any.

The messages you listed show blocks by Core Protections - see https://community.checkpoint.com/t5/Security-Gateways/IPS-Core-Protections/m-p/217103

They can not be avoided - this is expected behaviour. If you need to send Invalid packets or Illegal messages you have to avoid going thru the firewall...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events