- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Monitor action
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Monitor action
Hello Everyone,
What's difference between Monitor and Prevent?
I sometimes have the same event duplicate, one with monitor, and one with prevent. Other times I got only monitor, even if CheckPoint sees the targer URL as malicious. Does monitor block traffic too? Thanks.
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which product / blades / version is your query in relation to?
If you configuration is background mode potentially the first attempt could be detect and subsequent attempts prevent.
Anti-bot also has some different protections that might detect/prevent similar URLs.
Specifically in recent versions the logging for DNS trap for Anti-bot was changed to be Prevent where previously it was Detect.
More info (or even screenshots) is required to help guide you. 🙂
CCSM R77/R80/ELITE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please provide an example of at least one Monitor/Prevent pair.
