Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LeeBingKang
Advisor

Found some traffic prevented by optimized profile although didn't use it as firewall IPS profile

Hi Guys,

Recently, i found out a weird symptom whereby there are some logs mentioned prevented because of using "Optimized" profile although my firewall is using a custom profile. Meanwhile, the firewall version is R81.20 latest recommended Jumbo Hotfix.

image.png

image.png

Hence, I'm here seek for you suggestion on this matter.

 

Thank you.

0 Kudos
3 Replies
Timothy_Hall
MVP Gold
MVP Gold

That IPS protection/signature is a Core Activation (shield w/ firewall icon) instead of a ThreatCloud protection (shield icon).  Core Activations have their own separate profile not set by the Threat Prevention policy, the default one is "Optimized".  See here: https://community.checkpoint.com/t5/Threat-Prevention/Inspection-Settings/m-p/47720/highlight/true#M...

 

Gaia 4.18 (R82) Immersion Tips, Tricks, & Best Practices Video Course
Now Available at https://shadowpeak.com/gaia4-18-immersion-course
0 Kudos
LeeBingKang
Advisor

Hi Timothy Hall,

Thanks for your kind reply on my post. I got what you mean and below are some references for others to have a look in future.

image.pngimage.pngimage.png

 

0 Kudos
the_rock
MVP Gold
MVP Gold

Maybe just as a quick check, under tab for ips profiles once in smart console, right click on each profile and see "where used"

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events