- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Sweep Scan preventing
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sweep Scan preventing
Hello, I have a question, currently we se sweep scan logs, we have already configured the Host port Scan but it appears in Detect mode, it there a way to verify that it is actually blocking or is it normal that the logs show it in Detect mode and not Prevent mode ?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you have Smartevent, utilizing a response for external IP Sweeps to block the source IP address for a time you determine works great. I would advise the first time you do enable the feature in Smartevent, enable a response with an email to you so you can see the volume and make sure you would not block legitimate sources. Using Playblocks, in the portal.checkpoint.com, they have some automations for blocking that maybe what you are looking for if you do not have Smartevent. Obviously, you would need a license for Smartevent or Playblocks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are examining how to add this as a new automation to Horizon Playblocks.
It already includes automations to block attacks and scans such as:
https://www.checkpoint.com/horizon/playblocks/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The URL below, indicates the signature will only alert to the activity but not block. You can utilize Smartevent which will use SAM rules to block an IP address for configurable amount of time for IP Sweeps, port scans and other detections.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Makes sense, as it does not give option to block it from IPS protection itself in smart console.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So what can I do to block this type of scanning ??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe better to open TAC support case to get an official answer.
Regards,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you have Smartevent, utilizing a response for external IP Sweeps to block the source IP address for a time you determine works great. I would advise the first time you do enable the feature in Smartevent, enable a response with an email to you so you can see the volume and make sure you would not block legitimate sources. Using Playblocks, in the portal.checkpoint.com, they have some automations for blocking that maybe what you are looking for if you do not have Smartevent. Obviously, you would need a license for Smartevent or Playblocks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are examining how to add this as a new automation to Horizon Playblocks.
It already includes automations to block attacks and scans such as:
https://www.checkpoint.com/horizon/playblocks/
