- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: IPS Protection vs Check Point Advisories Archi...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS Protection vs Check Point Advisories Archive
Hi All,
I am writing to inquire about a discrepancy I have encountered while reviewing the checkpoint advisories archive and the checkpoint IPS protection.
While examining the advisories archive (https://advisories.checkpoint.com/advisories/), I attempted to locate specific CVE's on my IPS Protection However, despite my checkpoint IPS indicating that it is up to date, I was unable to find these CVE's within the IPS protection.
I would greatly appreciate it if you could shed some light on this matter and provide an explanation as to why these CVE's are not appearing within the IPS protection. It is important for me to understand whether this is an expected behavior or if there might be any issues with my current setup.
Please let me know if there are any additional details or steps that I need to consider in order to resolve this discrepancy. Thank you for your attention to this matter, and I look forward to your prompt response.
Thanks,
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi guys, I updated the IPS offline and now it shows me all the CVE from the checkpoint advisories. and the version info also updated to the latest one. The below link is to download the offline update package.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you please provide the CVEs you searched? I would like to check in my R81.20 lab.
Cheers,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just search randomly from the checkpoint advisories but I couldn't get the latest ones.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As @the_rock asked, please give a couple of examples so I can send to the relevant R&D owners to examine.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please provide the IPS package version, Gateway/Management version & JHF level in addition to the list of CVEs that you are attempting to locate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS Update Version: 635234643
Gateway/Management version: r80.40
JHF level: 192
regarding the CVE I just randomly search from the advisories and I couldn't find on the IPS Protection e.g CVE-2021-35218, CVE-2021-44026
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just checked R81.20 mgmt and found both of them
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To add to my last response, I would strongly urge you to upgrade to at least R81.10. So many fixes in it and even R81.20, Im super impressed with it now. Management, I would recommend to anyone, even gateways, but maybe better to wait until CP says R81.20 is officially recommended.
Either way, when it comes to IPS and app control, R81.10 is wayyy better than R80.40, just saying.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi guys, I updated the IPS offline and now it shows me all the CVE from the checkpoint advisories. and the version info also updated to the latest one. The below link is to download the offline update package.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the update. Most people have scheduled IPS updates enabled...if you dont, you definitely should set that up, its only few clicks.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I also make automatic update however the smart console shows me it is up to date while the threat prevention protection shows me there is missing update it confuses me. that's why I use offline update.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah, ok, that makes sense.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you are trying to search for CVE numbers directly on the IPS Protections screen of SmartConsole, be aware that at one point CVE numbers were not a searchable item and would not show up. This was resolved in the latest versions of the SmartConsole software in most releases so make sure you are running the latest one, especially since the R81 and earlier versions of SmartConsole do not notify you that SmartConsole software updates are available.
March 27th with sessions for both the EMEA and Americas time zones
