Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
demirdag
Participant

How to exclude IP from SAM rules

Hello everybody,

Following a big outage we noticed that our main gateways had put their own public IP subnet in the SAM ruleset. How can I prevent this from happening? Is there any way to exclude a subnet from being monitored for suspicious activity?

0 Kudos
2 Replies
Tal_Paz-Fridman
Employee
Employee

I would look at https://support.checkpoint.com/results/sk/sk112061 

How to create and view Suspicious Activity Monitoring (SAM) Rules

 

Try to see if -b flag with IP of Security Gateway works.

0 Kudos
the_rock
Legend
Legend

I agree with @Tal_Paz-Fridman . I would double check what you have as per short video I uploaded.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events