- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
hello everyone,
I have a problem with the profiles in Threat Prevention under Custom Policy. I created a profile some time ago: ‘JMC only IPS’. I have now removed the profile from all (known) locations. when I display a ‘Where Used’, I can see that this profile still exists in 2 objects:
SDT_asm_dynamic_prop_SSL_BF_DOS_JMC only IPS_attribs
SDT_asm_dynamic_prop_UDP_BF_DOS_JMC only IPS_attribs
It is not listed anywhere else, not under Policies or Legancy objects. Only under Objects.
I have no idea where to find them or what they do. I just want to delete the profile, but I can't do that.
strangely enough, i sometimes find entries in the logs that refer to this profile. for example in a log under ‘Protection Name: Non Compliant DNS’. when i look at the rules in the inspection settings, however, i cannot determine which profile is the basis anywhere. i have also already checked all other settings such as the layers, etc.
I have another profile with the same values, but it is being used.
Can anyone help me here?
thx
jeff
The protections in question are (what you've seen are the internal names):
Web Servers UDP Flooding Denial of Service
Web Servers SSL Flooding Denial of Service
Check to see if the Profile is somehow still active in each protection.
hello,
unfortunately that wasn't it. but you've given me an idea. i'm going to reactivate the profile and then switch off all the active rules manually. let's see if that helps.
thanks
jeff
hello,
too bad, the idea was good but it didn't help. all ips and core rules for the profile are now inactive. nevertheless, the entries are still there.
but if i think about these entries, then the BF_DOS could stand for ‘Brute Force’ and ‘Deny Of Service’.
but that doesn't help me at the moment.
thanks
jeff
You're probably right but as I wrote these are just the internal name for the following IPS Protections:
Web Servers UDP Flooding Denial of Service
Web Servers SSL Flooding Denial of Service
They are somehow still referenced.
You might want to look for your Profile name using the Database Tool (GUiDBedit). I advise not making any changes yourself, instead open support ticket with TAC:
https://support.checkpoint.com/results/sk/sk13009
hello,
ok, this will probably be a TAC. i have now deactivated everything. i have even switched off the ips in the profile so that no blade is active any more. i have also removed the profile from the policy.
i have looked at everything with GUiDBedit and there are entries exactly in the web servers ... flooding are present.
but it gets even better: after a restart i still get entries in the log with the profile ‘jmc only ips’. especially e.g. with squence verifier messages.
but the profile is no longer in use and everything is switched off.
thank's
jeff
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 19 | |
| 8 | |
| 7 | |
| 7 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY