- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Team,
Gateway Cluster Properties page: The IPS tab--> Activation Mode --> According to Threat Prevention policy or Detect only modes.
Does this setting take precedence to all the IPS configuration (inactive, detect, prevent) of signatures? Where is this setting described in the R80.30 Documentation?
Cheers!
It uses the configuration as follows: inactive is still inactive, detect stays detect (and is no good anyway, as it costs the same resources as prevent, but without much gain), and prevent gets changed to detect.
As Gunter says setting "Detect Only" temporarily causes IPS protections set to Prevent to act like Detect. As mentioned in my IPS Immersion series this function was called "Troubleshooting Mode" in R77.30 and earlier, and may still be referred to by that name in some places.
Hi,
you can find the information here: Threat Prevention R80.30 Administration Guide (checkpoint.com)
It actually only mentiones Anti-Bot and Anti-Virus but it's the same with IPS. When choosing "Detect Only" nothing is blocked but only logged and according to policy is obviously blocking traffic if you have configured it properly.
Yes that's the issue> I can't find any related info on the IPS settings. There are many settings on that page also
As Gunter says setting "Detect Only" temporarily causes IPS protections set to Prevent to act like Detect. As mentioned in my IPS Immersion series this function was called "Troubleshooting Mode" in R77.30 and earlier, and may still be referred to by that name in some places.
It uses the configuration as follows: inactive is still inactive, detect stays detect (and is no good anyway, as it costs the same resources as prevent, but without much gain), and prevent gets changed to detect.
Thank you G_W. Sounds like Threat Emulation setting to Detect does the same thing here.
@ Marcel - The settings for Anti-Virus and Anti-Bot aren't on this page and I per G_W what he mentions makes sense as far as the Firewall properties settings are concerned. CP has settings everywhere for everything and not very intuitional. I would say for majority common administrators this becomes a major headache unless you have a dedicated team of pros, tons of money for TAC and a forgiving workplace.
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY