We have Checkpoint R81.10. I use the SmartEvent but most of what is in there is default settings. Today I needed to make an exclusion for our outside PCI scanner and I saw the "Global Exclusions" options. I have 2 questions about this option,
First, and most important, is there is a rule in there for Log Id 2000 (any source, product, or destination). I did not make this rule and am wondering if it is a default one and what it does. I have not yet been able to find anything on it and it is kind of worrying me as I may be exluding something and not meaning to.
And second, I can't tell by the documentation if using the glabal exclusion just prevents the traffic from showing in logs or does it actually stop it from going thru all these threat preventions? I need it to do the latter. I have a rule in my IPS settings to prevent them from being stopped but it is still being stopped by a SAM rule and I want to add it here.
Any help is appreciated. I am still looking but that first question has me concerned.