- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- IPS utilization report - Smart View
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS utilization report - Smart View
Hey all,
I believe that most of us that enabled IPS in our environment, asked one of the following questions:
- "if I will move to prevent, what will happen to my network"
- "Should I do it a step-by-step? how?"
- "is there any tool that i can use to eliminate any potential impact on my network"
for those question we have created multiple documentations with formal procedures.
Now, we have created a new Smart View report that allows you to understand your IPS utilization status and base on different step-by-step procedures, utilize the blade for maximum protection and minimum business impact.
You can download the CPR file (for Smart-View) from the following link:
If you want to influence, you are welcome to replay to this blog with any insight or change you believe we need to add/change. we will change the report based on your needs and will upload a new one until we will have a report that will be release as part of the next GA + Jumbo.
Thanks,
Oren
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Could you also share what are the documents with formal procedures that you mention were already created??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey,
this post will assist 🙂
have you managed to import the template? any inputs/changes needed?
Thanks,
Oren
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For all the IPS protections mentioned in the report the IPS detail descriptions including CVE numbers should be included as well. These are shown in the IPS protections list within SmartConsole but are not part of any report.
When sitting in C-level meetings to decide which IPS protections the firewall admins have to take care of and change from detect to prevent most people don't know what a specific IPS protection does, how critical the relevant protection is and so on. For two years now we are screen shotting the IPS protection details manually and include them in the report as image references, which is a very time consuming process.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey,
added the CVE into the report (see the attached image)
can you please elaborate on the second thing a bit more?
Thanks,
Oren
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the second thing was about the IPS Threat Description as shown here:
How can we add this to the SmartEvent report?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey,
the data we have in the log is name of the signature only.
we cant query from Smart-View on the IPS signatures DB that is presented in the list of IPS protections.
does the name and information on the signature is not enough? i just think on the quantity of text that we will present in the report and it will be A LOT
what do you think?
Thanks,
Oren
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
