- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hello all,
we are using SmartEvent in our R80.20 Jumbo Hotfix Take 118 enviroment for quite a while to track suspicious activities such as DoS attacks.
Like designed for DDoS attacks, we use the automatic reaction "block event activity", to block multiple sources for this type of event. Unfortunately, when such an event occures, the automatically created SAM rule in SmartviewMonitor only rejects the traffic. When manually creating a SAM rule, you can configure the type of action (Notify/Reject/Drop).
I couldn't find the option in the R80.20 Logging and Monitoring AdminGuide or anything else, to (globally) set this Action from SmartEvent created SAM rules from Reject to Drop. Does anyone have an idea?
Best regards
Oliver
This is a great question and sad no one got to answer it. I'm yet to find a workaround, I also want to drop instead of reject.
Hi everyone,
Even that this post is old I am hoping for an answer. Currently we are using SmartEvent R81.20, and we have the same issue.
We want to block source and drop the traffic, but automatically only it rejects it. Does anyone have an idea how to change reject to drop?
For security resons this is not effective for us.
Hi all,
I know this is an old post, but we have the same issue. We are using SmartEvent in our R81.20. For security reasons, we want to "Block Source" and Sam rules from Reject to Drop. Do we have any solution for this?
samv2 can drop traffic instead of samv1 that only can do reject. BUT samv2 is for example not supported to block port scans. Example: https://support.checkpoint.com/results/sk/sk110873
If have seen cases that it is possible to run sam alert v1 drop with custom patch. The only way is to open TAC case.
So if you use samv1 alert it is NOT possible to drop without patch.
Maybe instead of using block event/source you can try to execute external script and create SAM rules manually:
Dear @Amir_Senn and @the_rock
Thank you for your reply,
We do test the SAM rule option, I will update with our progress, negative or positive.
I was thinking, it will be great to implement a feature where a user is given the option to choose preferred action (e.g. reject, drop) when it create a new Object -> Automatic Reaction under SmartEvent.
Yea, agree with that.
You really got me curious now. I never really thought about this much, but will check it tomorrow in my R82 lab, as I have dedicated SE server.
Andy
Just tested in R82 and it appears its the same. You can do it manually via SV monitor and it will show as drop action, as @Amir_Senn had stated.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY