- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Ant-Virus on MTA: Medium Confidence always "Detect...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ant-Virus on MTA: Medium Confidence always "Detect" instead of "Prevent"
Hi all,
i am facing the below problem.
I have Sandblast appliance where it acts as MTA , and I have all the blades enabled (AntiBot, AntiVirus, Threat Emulation, Threat Extraction). IPS blade is disabled on the SG so not functional.
I have created the below profile:
I have the problem mentioned on the title.
I would expect my AntiVirus blade to Prevent anything with a Severity of medium to Critical and Confidence Medium to High.
Although it is working fine for High-High or Critical -High it is not predictable for Medium severity.
I have logs that is Prevent and others that are Detect. The only difference i ve noticed is the "Risk" were in the prevent logs is above 90 and in the Detect is around 80. But i am straggling to find any documentation that proves this.
I have read similar issue in CheckMates for threat Emulation and there are multiple explenations about the way the mail is delivered(Rapid vs Hold) but AntiVirus has not such a setting.
I am surely missing something but just cant figure it.
Any help please.
Thanks,
- Labels:
-
Anti-Virus
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you please share one of the detect logs in more detail?
Please redact any sensitive parts...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Apologies I can't really make out the screenshots and the risk levels on my mobile device.
Thomas describes a similar case here that he reviewed in debugs, risk of above 80 should yield prevent unless something was changed.
https://community.checkpoint.com/t5/Threat-Prevention/SandBlast-and-links-inside-email/td-p/15798
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are having a similar experience in our installations,
From the logs I've seen so far I can tell that the risk should be over 90 in order to get blocked!
Can someone from Checkpoint confirm this??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have enquired internally, please raise or share corresponding TAC SR details (via PM).
/Edit: Based on feedback recieved 90 is expected threshold here based on the profile configuration shown above.
