- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
#There is a confusion with our SCADA support definitions.
So, let’s use the following update from R&D to make some order in this repeated question.
We have 3 levels of Protocol support by Application Control Blade:
All the 4 protocols below are identified in the 3 levels:
Protocol | Ability to identify protocol | Ability to identify commands within protocol | Ability to identify parameters within protocol |
Modbus | YES | YES | YES |
IEC104 | YES | YES | YES |
DNP3 | YES | YES | YES |
CIP | YES | YES | YES |
As you can see below, the ability to Log detailed information (Addresses and Values) and supply high visibility (in DPI level), doesn’t equal to our ability to Enforce policies based on all details – See the differences in the following tables:
Ability to log:
Protocol | Unit ID | Function | Address | Group | Value |
Modbus | V | V | V |
| V (only for registers) |
IEC104 | V | V | V |
| V |
DNP3 |
| V | V | V | V |
CIP | V | V | V |
| V |
Ability to enforce :
Protocol | Unit ID | Function | Address | Group | Value |
Modbus | V | V | V |
| V (only for registers) |
IEC104 | V | V | V |
| V |
DNP3 |
| V | V | V |
|
CIP | V | V | V |
|
|
SCADA Set-Up and Troubleshooting
For Management Side:
For Gateway Side:
Feel free to ask any question you might have.
Thanks to Mati Epstein for this elaboration
This is great information, thanks for sharing!
Hey https://community.checkpoint.com/people/eyalre2474d7c-0b58-4fab-8e04-107bb8721a28 do we have any commentary on why the status for logging and enforcement is in the current status? and any plans for modification or enhacement?
Hi i'm not sure what do you refer in:
"...the status for logging and enforcement is in the current status? "
If you referred to the Ability to log and Ability to enforce tables above, pls. note they are not completely the same...
Regarding modification or enhancements if you have special requests please issue RFE
Hi,
Can we do this on R80.10?
MM
Thanks a lot!! is it possible with R80.10?
Hi,
can you please update instructions as sk106020 was removed?
Best Regards
MM
As of today the sk106020 access level is internal. Am sure this will change, but for now you'll have to contact your Check Point rep to get access.
hth,
bob
Given that sk106020 is now internal, is the above process still the Check Point endorsed method of delivering their ICS solution? If so it seems very prohibitive.
Yes, The process is the same.
We work to simplified the clean I.
Yet the policy setting will be the same.
Best Regards,
Eyal Rashelbach
Hey Bob !
Any "public" release date for the SK as we urgently need it, and asking our rep will take too loooooonnnnnnggggg...?
🙂
TIA
Best Regards
David
Can this be done on a 1200R appliance standalone?
Here, you do have a Applications & URL Filtering category "SCADA Protocols" - but you can not see what it contains. sk105738 lists: Application Control: Introducing the extended ICS SCADA offering with over 10 protocols (e.g: Modbus, DNP3, OPC, IEC-104, etc.), 500 command-level monitoring as well as granular parameter visibility of Modbus traffic.
But there is no mentioning of SCADA neither in Local or Central Admin Guide nor in any sk...
Hi Guenther,
could please explain me what is the issue you are claiming above?
do you want to know what is the SK which describe the extended SCADA capabilities?
Hi Shlomi,
i claim no issue, but wrote that the only place i found referring to SCADA details is sk105738 - so if you you know the SK which describe the extended SCADA capabilities fpr Embedded GAIA devices, please let me know!
Can someone please point me to the documentation to change Level 2 & Level 3 settings for ICS protocols when using R80.10 MDS and R80.10 Gateway versions? We see this is possible with R77.30 but are missing the information for R80.10.
Some of those settings are not yet available in R80.10 (particularly the Level 3 settings).
level 3 settings are available in R80.10 and it is possible to develop a SCADA application by CLI (no UI yet)
Is there docs we can point at that explains how to do this?
you can find it [linked removed by admin]
Is that info available externally for customers?
Could you please post some of the commands required to achive that, on version 77.30 I just needed o modify the database to get those options.
Pablo.
In 77.30 you needed to install a specific HF and then you had UI for generating DPI applications.
In 80.10 after you install the HF, you are able to generate the DPI application but without UI using CLI.
The CLI syntax can be found in the document I attached yesterday.
Examples:
mgmt_cli add scada-application name modbus_unit_3 scada-properties.0.key protocol scada-properties.0.value Modbus scada-properties.1.key unit scada-properties.1.value 3
mgmt_cli add scada-application name cip_function_4 scada-properties.0.key protocol scada-properties.0.value CIP scada-properties.1.key function scada-properties.1.value 4
thanks for the information
Shlomi, this must be an internal link because it does not take me anywhere.
It's an internal link.
Shlomi Feldman can you share the relevant details from that link to CheckMates?
I think this is an internal site as pointed by PhoneBoy in his comment below. I was unable to access it.
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY