- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Access policy matching and IPS autonomous
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Jump to solution
Access policy matching and IPS autonomous
Hey Checkmates,
i have a question regarding access policy matching in conjunction with IPS ( autonomous mode)
I have blocked traffic from an known malicious IP in an access policy.
I can see that the relevant traffic is dropped but nevertheless the traffic hits the IPS blade.
Is this a expected behavior?
I thought that no further inspection is going on, when the traffic is dropped by the access rule.
Thanks in advance
Stephan
1 Solution
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
4 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you able to share a copy of the redacted log card for review, which protection is matched?
CCSM R77/R80/ELITE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just found that transit traffic is dropped like expected and not hitting the IPS blade.
Traffic to the gateways seems to be handled different , as this is inspected by IPS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes most likely due to some implied rules.
CCSM R77/R80/ELITE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you.
