Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dbran_2903
Explorer

How have you resolved port scanning issues in a VSX environment?

I have noticed that SAM Rules do not work in a VSX environment, and so far, I have not found any alternative solutions. I would like to prevent port scanning on a specific Virtual System. While the Core Protection 'Host Port Scan' signature does exist and can be modified from 'Inactive' to 'Accept,' according to SK110873, a SAM Rule must be created for it to take effect. What other solutions exist to address this issue?

 

Topology:

-Maestro enviroment

-Security Group as VSX mode (4 Gateways)

-Many Virtual Systems is running

 

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

The only thing the "prevention" does is issue a block to the relevant IP address (why it needs a SAM rule).
You can do something similar with rate limiting: https://support.checkpoint.com/results/sk/sk112454
Granted, it's not tied to the specific Core Protection, though.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events