Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
George_Ellis
Advisor

Test via snmpwalk or cli if IPS Bypass is set to track via SNMP alert

The reason:  Auditors

I am trying to figure out how to batch test on gateways that have IPS installed if Bypass is set to track to SNMP alerts.  (see attachment).  I have walked through the Check Point mibs and tried to see if any of the IPS cli commands expose it.  No joy.  I could have missed it.

We use Backbox, so anything I can do at the CLI, I can execute.  I can also snmpwalk the device.  But still trying to figure out what to test against.

Any clues CM crew?

 

Does not give what you need, but the test is:

ips bypass stat

Test for "Disabled", "Enabled", "IPS Blade is disabled"

 
 

 

0 Kudos
1 Reply
Lesley
Mentor Mentor
Mentor

Screenshot here shows the SNMP MIB for IPS. I would assume if the IPS goes into bypass one of those values will change.

Would give this a go, load the system up with traffic to force a bypass and see if this changes the value. If so you can use that one.

https://community.checkpoint.com/t5/Threat-Prevention/SNMP-MIBS-for-IPS-Blade/m-p/89845#M2723

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events