- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have started to use the Optimized Profile for my IPS, however I have noticed protections that should be enabled according to the Check Point IPS Update email, yet its actually inactive.
Please see example.
Advantech WebAccess SCADA Stack-based Buffer Overflow
(CVE‑2019‑3975: CVE‑2019‑3951) should be set as activated but has not been.
Anyone know why this would be case and how I could fix this?
Thought I would reply with the the reply from TAC incase anyone was interested:
This is indeed the thing I was planning to check on the Protections. Optimized profile does not automatically enable Protection under "Product Prevalence - Scarce", only Common, as to not impact Firewall productivity with a load.
"Strict" Profile is the one that has all protection enabled by default.
You can either switch to Strict profile or re-configure Optimized profile (by cloning it).
I also raised the question about why on the IPS News Emails sometimes the Protections are ticked or not next to the relevant Protection/Profile and this was the reason:
I reached people responsible for this email feed, and the 'tick' on the Profile does not mean the Protection is enabled by default - those configurations are to be done by user on SmarConsole. Note that "tick' is also on Basic Profile, which has less amount of Prevent by default.
As to what 'tick' means exactly, unfortunately I cannot say.
Hope this helps anyone else if they were interested.
Thanks for the comment but that's not the case.
My setting is the same as yours:
Newly downloaded protections will be set to - Active - According to profile settings
From my screenshots, the other 2 IPS protections are set according to the policy but one of them isn't.
Looking at the 2 High ones, 1 is set and 1 isn't. They are the same on Performance Impact, Severity and Confidence Level so they should both be set as Active but my policy decides to leave one as inactive and I can't see a reason why.
I have others as well but only raised this now to see if anyone else can see a reason as to why.
I would ask TAC for an explanation !
Hey,
This protection is not a part of Optimized profile as it does not have "Product Prevalence: Common" tag.
Thanks
Shiran
Thought I would reply with the the reply from TAC incase anyone was interested:
This is indeed the thing I was planning to check on the Protections. Optimized profile does not automatically enable Protection under "Product Prevalence - Scarce", only Common, as to not impact Firewall productivity with a load.
"Strict" Profile is the one that has all protection enabled by default.
You can either switch to Strict profile or re-configure Optimized profile (by cloning it).
I also raised the question about why on the IPS News Emails sometimes the Protections are ticked or not next to the relevant Protection/Profile and this was the reason:
I reached people responsible for this email feed, and the 'tick' on the Profile does not mean the Protection is enabled by default - those configurations are to be done by user on SmarConsole. Note that "tick' is also on Basic Profile, which has less amount of Prevent by default.
As to what 'tick' means exactly, unfortunately I cannot say.
Hope this helps anyone else if they were interested.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY