- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- SAM rules and IPS
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SAM rules and IPS
I would like if you could clarify an issue regarding the inspection performed by the IPS engine and the complementary operation with the SAM rules, because through logs we can see that the traffic that checks with some SAM rules then appears in a log as detect for the IPS rules, in which it should be prevent, according to the profile and rules applied.
Is this behavior correct if the SAM rule is applied first?
Thanks
Labels
- Labels:
-
Quantum
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What version/JHF?
What precise IPS protections are involved using what Threat Prevention profile and rules?
In any case, SAM rules should apply first.
Screenshots (with sensitive details redacted) will help.
