Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Msin3
Explorer

Why Do You See Two IPS Events in the Log: One as "Detect" and Another as "Prevent"?

Hi CheckPoint Mates,

Can you plz explain, although I have set the Threat Prevention IPS Protection to Prevent mode for Low, Medium and High Critical severity still while analyzing the logs I see first log as Detect and rest all other logs to Prevent.

Why is this behavior observed ? How to much time does Checkpoint takes to verify the packet/traffic to be anomaly and detect and block it.

 

Regards,

Mohsin Nawaz

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Threat Prevention has two modes:

  • Background (allows the traffic to pass until classified)
  • Hold (will not allow traffic to pass until classified)

If you were to hold a DNS request, the end user would experience a delay while we do a lookup to ThreatCloud.
This does not take long (and we cache the result), but in this case, it appears you are running in Background Mode (believe this is the default) and the DNS request/response completes before this lookup completes.
This is expected behavior.

You can change to Hold mode as shown here, though it will likely impact end user experience.

image.png

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events