- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I am searching for ideas to inform our users, when a IPS protection takes effect - like Usercheck is doing it.
Thanks for any ideas
Martin
Would you like to notify the Security Administrator or the user that triggered the specific IPS Protection?
Hey,
You can get it from Smartevent and trigger the notification when the action is matched.
Go to the Log & Monitor Tab -> Smart Event Settings & Policy
Create action as Email and then you can defined the triggers there
Hi @Blason_R ,
This IPS reaction cannot have dynamic e-mail addresses, can it?
Means that if a user blocked by the IPS can it be notify to the specific user in every case.
As discussed it's not really geared for end user notification, rather the SOC etc.
Thanks, 🙏
Many attacks for which IPS applies may not be due to an interactive user session or in a browser.
Whilst UserCheck provides both an agent and email configuration options it's currently most relevant to the likes of Anti-virus / Anti-bot in the Threat Prevention context.
The IPS blade is not capable of sending UserChecks to the end user, and will simply start dropping packets or in some cases issue a TCP reset (whether a particular IPS protection performs a drop or reject upon a prevent action cannot be changed). So if a user gets blocked but doesn’t seem to see a UserCheck, the IPS blade may well be responsible. This was covered in my IPS/AV/ABOT Immersion course.
That was exactly my motivation for asking this question. But as already answered, the only way to notify my users that an IPS protection has blocked a specific connection is with SmartEvent notifications. But how do I inform the users without installing an agent... Email would be ok, but I need to map the client's IP address to the user - So I need IA Blade active! (?) plus a script that collects the appropriate information. Sounds complex and maybe things changes in a future release ...
Thanks for all your answers !
I agree with @Blason_R . I see same options in R81.20 as well and seems best way to do this.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 28 | |
| 15 | |
| 13 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY