Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marella_0305
Explorer
Jump to solution

What is meant by Checkpoint Default Protection?

Hi Mates,

Hope all are doing well!

I have recently observed some drop logs in my smart console logs & monitor tab with firewall blade.

The drop logs occurs due to TCP Invalid Checksum. When I refer some sk's regarding this the sk describe due to Checkpoint firewall default protection the packets were dropped.

Name: Streaming Engine TCP invalid Checksum

Information: Invalid checksum. Packed dropped

My consideration is on what basis does checkpoint default protection works? What is exactly means of Checkpoint Default Protection?

Is there separate default protections for each blade/software in Checkpoint? 

Kindly, can any one explain?

Please bear my English, if any mistakes in writing this!😊

 

Thanks & Regards,

Saisarath

0 Kudos
3 Solutions

Accepted Solutions
Alex-
Leader Leader
Leader

This is the built-in IPS of the Firewall blade, you can check the protections and their activation status in the Security Policies view, under Shared Policies - Inspection Settings.

View solution in original post

796570686578
Collaborator

Those are protections that are in place whether or not you have Threat Prevention active. Therefor these Protections are installed with the Access Control Policy and not the Threat Prevention Policy.

You can find them by going to the "Security Policies" tab -> and under Shared Policies -> "Inspection Settings"

View solution in original post

Timothy_Hall
Legend Legend
Legend

There are four classes of what are commonly considered IPS protections/signatures:

1) IPS ThreatCloud Protections (15,000+ and always increasing)

2) Core Activations (39)

3) Inspection Settings (146)

4) Geo Policy (deprecated and replaced by Geo Updatable Objects)

The Default_Protection profile is related to Inspection Settings.  How you deal with each of these classes (profiles, creating exceptions, etc) is quite different and nicely covered in the upcoming 2-day Check Point Threat Prevention Specialist class, that should should be released to Check Point ATCs worldwide at the end of this month.  Highly recommended!

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

(1)
5 Replies
Alex-
Leader Leader
Leader

This is the built-in IPS of the Firewall blade, you can check the protections and their activation status in the Security Policies view, under Shared Policies - Inspection Settings.

796570686578
Collaborator

Those are protections that are in place whether or not you have Threat Prevention active. Therefor these Protections are installed with the Access Control Policy and not the Threat Prevention Policy.

You can find them by going to the "Security Policies" tab -> and under Shared Policies -> "Inspection Settings"

Timothy_Hall
Legend Legend
Legend

There are four classes of what are commonly considered IPS protections/signatures:

1) IPS ThreatCloud Protections (15,000+ and always increasing)

2) Core Activations (39)

3) Inspection Settings (146)

4) Geo Policy (deprecated and replaced by Geo Updatable Objects)

The Default_Protection profile is related to Inspection Settings.  How you deal with each of these classes (profiles, creating exceptions, etc) is quite different and nicely covered in the upcoming 2-day Check Point Threat Prevention Specialist class, that should should be released to Check Point ATCs worldwide at the end of this month.  Highly recommended!

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
(1)
the_rock
Legend
Legend

All the guys said it best, you definitely got great explanations.

Andy

0 Kudos
the_rock
Legend
Legend

I will add though, the BEST option to protect against ddos is to change inspection profile from default to recommended. You may need to add some exception aftewards, but thats an easy part.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events