- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- R80.10 Threat prevention policy enforcement order
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R80.10 Threat prevention policy enforcement order
Hello,
Can you please clarify the order of processing rules in R80.10 Threat Prevention policy, using single layer?
For example, if the first rule(where only Threat Emulation is enabled in profile) is matched, will other rules be checked?
I mean, other rules with Antivirus, for instance.
So, the rule base will look like this:
1 any any Profile1(Threat Emulation only)
2 any any Profile2(Antivirus and IPS)
Will traffic be checked with Antivirus and IPS here?
Thank you in advance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, it depends on the type of the traffic.
IPS traffic will look for the IPS rule. AV traffic will look for the AV rule, etc.
regarding multiple layers and rules, see https://community.checkpoint.com/message/16963-re-editing-policy-from-no-layers-to-2-layers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Tomer!
