- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- How packet flow works inside the IPS blade..?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How packet flow works inside the IPS blade..?
Hello Everyone,
I am troubleshooting one of the issue that involve the IPS.
But I'm unable to understand the IPS behaviour in terms of packet flow inside the IPS blade.
Can anyone share the IPS structure in Checkpoint firewall?
The administrative document does not explain well instead of configuration.
Regards,
B
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- SecureKnowledge sk95193: ATRG IPS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi B,
I take it that you have already consulted the ATRG IPS document and that it has not provided you with the requested information.
Could you elaborate for us what is the exact problem you are facing please in case we can help?
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As far as IPS and its related features, it goes more or less like this in R80.10+:
1) Geo Policy Enforcement
2) Inspection Settings enforcement as part of Access Policy
3) Core Activations & ThreatCloud Protections early in the Threat Prevention policy
Please provide what problem you are looking to solve and the gateway version, as IPS is implemented quite differently in R77.30 and earlier.
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
More technical, but still very simplified steps. Go ahead and read the IPS ATRG as recommended earlier.
- Passive Streaming (PSL)
- Re-ordering of packets
- Unified Streaming and ASPII
- US decides which parser will handle this traffic
- ASPII decides which protections to run for this traffic
- Protocol Parsers
- Parse protocols for RFC compliance etc. and recognize contexts.
- Inspection settings and core protections are executed here.
- CMI
- Receives contexts from parsers.
- Executes relevant protections to traffic
- Returns result to parsers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See also the following
https://community.checkpoint.com/t5/General-Topics/Security-Gateway-Packet-Flow-and-Acceleration-wit...
https://community.checkpoint.com/t5/General-Topics/R80-x-Security-Gateway-Architecture-Logical-Packe...
