Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
PhoneBoy
Admin
Admin

Legitimate URLs Blocked with Recent AV Update

An Anti-Virus signature was recently published that caused a number of legitimate sites to be blocked, impacting gateways worldwide.

Specifically, you will see the following symptoms:

  • Anti-Virus blocks legitimate traffic with DNS trap or DNS reputation logs.
  • Many logs of Anti-Virus are getting created on DNS trap and DNS reputation with the protections "REP.ikjuju" and "REP.ikktgp".

Check Point has removed the relevant signature from the database. Perform the steps in the following SK to ensure the AV database is updated: Anti-Virus blocks legitimate traffic with DNS trap or DNS reputation logs 

2 Replies
Alex_Alborzfard
Contributor

Since the impact of this was worldwide, as you stated, I'm wondering why the customers were not notified?! We were affected by this. We spent half a day on troubleshooting & fixing the issue. This would've saved us few hours on a Sunday! Smiley Sad

Thomas_Allen
Participant

Does anyone know what time Checkpoint release the fixed signature file?  Trying to finalize paperwork on this.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events