- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- IPS - Basics Protections
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS - Basics Protections
Hello
I want to know if there are some specific information about basic IPS Signatures.
We have an external IPS (Main) but we need to enable some signatures in CheckPoint Firewall to protect if any signature escaped from the main IPS.
Thanks.
Regards.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have like 9000 signatures (or more maybe). I highly suggest you to check which protections are enabled the IPS default profile.
You can also use filters or categories to see specific signatures (ie: linux, wordpress, etc)
Hope it helps
_____
https://www.linkedin.com/in/federicomeiners/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Federico.
And from the Inspection Settings from "Shared Policies". I would like to protect my infraestructure from attacks like SYN FLOOD.
How its works de Inspection Settings signatures?
Thank you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First off, I'm assuming that you are using R80.10 or later on your gateway. In R80.10+ there are essentially four separate types of signatures/protections that were formerly all part of IPS in R77.30 and earlier:
- IPS ThreatCloud Protections (part of Threat Prevention)
- Core Protections (part of Access Control...sort of)
- Inspection Settings (part of Access Control)
- Geo Policy (part of Access Control)
If you still have R77.30 or earlier gateways management of IPS is much more complicated. I'm happy to answer specific questions about IPS that were covered in my IPS Immersion course, but I'd suggest reading the relevant Check Point IPS documentation first as this is a rather large topic.
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My version of gateway is R80.20SP and the managment also.
We have a 64000 appliance. My specific question is for Inspection Settings (part of Access Control).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would study the following:
R80.30 Next Generation Security Gateway Guide
sk106597: Best Practices - Rulebase Construction and Optimization
sk112241: Best Practices - DDoS attacks on Check Point Security Gateway
sk43733: How to measure CPU time consumed by IPS protections
