Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
-K-
Contributor

Is there any tool or script to trigger IPS signature directly from Checkpoint gateway to test IPS

Is there any tool or script to trigger IPS signature directly from Checkpoint gateway to test IPS functionality in a large scale environment.

I know Ping protection but it would be hard to find backend machine which will initiate a traffic towards machine behind FW to get the IPS trigger and allowing in access rule for that traffic and all which is too much time consuming.

Any other/alternative script / curl command or something suggestion which can trigger the IPS event from gateway itself without much changes ?

Please suggest.

Appreciate your input and suggestion.

0 Kudos
7 Replies
Cyber_Serge
Collaborator

Not sure if you are trying to test specific IPS Protection, but you can try using the below link to test effectiveness of your gateway and configuration:

https://pages.checkpoint.com/checkme-instant-security-check.html

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Per sk115236 CheckMe will attempt to trigger the following IPS protection.

"D-Link 850L Router Remote Unauthenticated Information Disclosure"

CCSM R77/R80/ELITE
0 Kudos
-K-
Contributor

I am afraid as this will do test from a machine which is behind specific firewall only but i wanted to have some script or some ways which will trigger from firewall gateway it self without opening any communication flow and trigger some ips signature to validate the ips functionality on 200+ gateways (offcourse i ned to login to individual firewall/gateway but still ok instead of finding machine behind 200 gateways. Hope i defined the requirement clearly.

 

By the way thank for your input 🙂

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Do you do any testing with the URLs in that SK via curl or similar?

Note there is also a cross-site scripting protection test listed there.

CCSM R77/R80/ELITE
0 Kudos
PhoneBoy
Admin
Admin

So, let me get this straight: you want to trigger an IPS protection...any protection...from the gateway itself?
Did you try, e.g. a large ping from the gateway itself?

0 Kudos
-K-
Contributor

Yes thats right. thats the requirement.

0 Kudos
-K-
Contributor

I would like to perform test on multiple lets say 200+ firewalls directly from firewall/gateway for IPS funtionality test if there is no events.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events