- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Everyone,
We are not clear with a different meaning on the keyword in Check Point such as Redirect, Detect, Drop, Block, and Prevent. Could you help to explain that keyword?
Thank you in advance!
Detect and Prevent relate to the various Threat Prevention blades.
Prevent means block malicious traffic according to the configured Threat Prevention profile/settings.
Detect flags such traffic the logs but does not impede.
Redirect relates to UserCheck messages in logs (i.e. instead of seeing the webpage you desire, you are redirected to a Captive Portal).
Drop usually applies to Access Policy and means traffic does not get passed by the gateway.
Block is basically the same thing.
Context matters in all of the above, but that’s their general meaning.
Context is important. Are you talking about certain specific blades? Also, did you read documentation and/or searched this community before asking this question?
Thank you for your answer!
We already searched on that keyword, but not found.
Detect and Prevent relate to the various Threat Prevention blades.
Prevent means block malicious traffic according to the configured Threat Prevention profile/settings.
Detect flags such traffic the logs but does not impede.
Redirect relates to UserCheck messages in logs (i.e. instead of seeing the webpage you desire, you are redirected to a Captive Portal).
Drop usually applies to Access Policy and means traffic does not get passed by the gateway.
Block is basically the same thing.
Context matters in all of the above, but that’s their general meaning.
Maybe I can explain Redirect a bit more in detail.
If you have a blade configured to Block/Prevent something (Anti-Virus, URL-Filtering, whatever) the gateway sends a redirect to the client to show the blockpage. If this redirect is not followed by the client, then the action in the log is redirect, telling you that he didn't saw the block.
The reason for this that the blocked/prevented connection is either a background connection (not done by a browser) or a part of the page like advertisements, etc. and because of that not followed by the browser.
Hey DWA, with Drop, I was under the assumption the gateway just swallows the packet without notifying the sender/source.
With Block, the gateway drops the packet and sender/source is given a response.
Is that correct?
Drop can only be done for unestablished connections, and yes, no response is set.
Block is similar to Reject, meaning a TCP Reset or ICMP Unreachable is sent.
The primary difference: Reject is for unestablished connections, Block is for established ones.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 8 | |
| 7 | |
| 7 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY