Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
demirdag
Participant

How to exclude IP from SAM rules

Hello everybody,

Following a big outage we noticed that our main gateways had put their own public IP subnet in the SAM ruleset. How can I prevent this from happening? Is there any way to exclude a subnet from being monitored for suspicious activity?

0 Kudos
4 Replies
Tal_Paz-Fridman
Employee
Employee

I would look at https://support.checkpoint.com/results/sk/sk112061 

How to create and view Suspicious Activity Monitoring (SAM) Rules

 

Try to see if -b flag with IP of Security Gateway works.

0 Kudos
the_rock
Legend
Legend

I agree with @Tal_Paz-Fridman . I would double check what you have as per short video I uploaded.

Andy

0 Kudos
PhoneBoy
Admin
Admin

As far as I know, there shouldn’t be anything automatically creating SAM rules against your gateway IP.
There is nothing preventing you from doing so via the fw sam command, however.

0 Kudos
HeikoAnkenbrand
Champion Champion
Champion

To prevent your main gateways from including their own public IP subnet in the SAM ruleset, you can exclude specific subnets from being monitored for suspicious activity by configuring exceptions in the SAM rules. Here's how you can do it:

  1. Access the Security Management Server:

    • Open SmartConsole and connect to your Security Management Server.
  2. Navigate to SAM Settings:

    • Go to "Logs & Monitor" and open the SmartView Monitor.
  3. Open Suspicious Activity Rules:

    • Click on the "Suspicious Activity Rules" icon in the toolbar to open the Enforced Suspicious Activity Rules window.
  4. Add an Exception:

    • Click on "Add" to create a new rule.
    • In the "Block Suspicious Activity" window, specify the source and destination IP addresses or networks you want to exclude. Use the IP and subnet mask fields to define the subnet you wish to exclude.
  5. Configure the Rule:

    • Set the action to "Notify" instead of "Block" for the specific subnet you want to exclude.
    • Set an expiration time for the rule to ensure it doesn't affect performance unnecessarily.
  6. Enforce the Rule:

    • Click "Enforce" to apply the rule to the selected Security Gateway(s)
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events