- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi All,
How to proceed if I want to block an ip address immediately in FW. In both GUI and CLI is this possible?. Help me to learn. Thank You.
Hi,
this is possible via GUI and CLI. If you wan to solve this via CLI and you are running R80.20 have a look at this
R80.20 - IP blacklist in SecureXL
For other Versions this would apply
Accelerated Drop Rules Feature in R75.40 and above
If you want to do this via GUI you can use SAM Rules. Open SmartView Monitor -> Launch Menu -> Tools -> Suspicious Activity Rules -> Add. Further Reading here
How to create and view Suspicious Activity Monitoring (SAM) Rules
Use with caution 🙂
Hi,
Please create SAM rule in firewall. It will immediately block IP. Refer SK112061 for more information.
Thank You Gaurav...
Hi,
this is possible via GUI and CLI. If you wan to solve this via CLI and you are running R80.20 have a look at this
R80.20 - IP blacklist in SecureXL
For other Versions this would apply
Accelerated Drop Rules Feature in R75.40 and above
If you want to do this via GUI you can use SAM Rules. Open SmartView Monitor -> Launch Menu -> Tools -> Suspicious Activity Rules -> Add. Further Reading here
How to create and view Suspicious Activity Monitoring (SAM) Rules
Use with caution 🙂
Thank You Benedikt for making clearly understand...
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY