To prevent your main gateways from including their own public IP subnet in the SAM ruleset, you can exclude specific subnets from being monitored for suspicious activity by configuring exceptions in the SAM rules. Here's how you can do it:
-
Access the Security Management Server:
- Open SmartConsole and connect to your Security Management Server.
-
Navigate to SAM Settings:
- Go to "Logs & Monitor" and open the SmartView Monitor.
-
Open Suspicious Activity Rules:
- Click on the "Suspicious Activity Rules" icon in the toolbar to open the Enforced Suspicious Activity Rules window.
-
Add an Exception:
- Click on "Add" to create a new rule.
- In the "Block Suspicious Activity" window, specify the source and destination IP addresses or networks you want to exclude. Use the IP and subnet mask fields to define the subnet you wish to exclude.
-
Configure the Rule:
- Set the action to "Notify" instead of "Block" for the specific subnet you want to exclude.
- Set an expiration time for the rule to ensure it doesn't affect performance unnecessarily.
-
Enforce the Rule:
- Click "Enforce" to apply the rule to the selected Security Gateway(s)
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips