We have Checkpoint R81.10. I use the SmartEvent but most of what is in there is default settings. Today I needed to make an exclusion for our outside PCI scanner and I saw the "Global Exclusions" options. I have 2 questions about this option,
First, and most important, is there is a rule in there for Log Id 2000 (any source, product, or destination). I did not make this rule and am wondering if it is a default one and what it does. I have not yet been able to find anything on it and it is kind of worrying me as I may be exluding something and not meaning to.
![global exception.jpg global exception.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/25330i800E601676E25254/image-size/large?v=v2&px=999)
And second, I can't tell by the documentation if using the glabal exclusion just prevents the traffic from showing in logs or does it actually stop it from going thru all these threat preventions? I need it to do the latter. I have a rule in my IPS settings to prevent them from being stopped but it is still being stopped by a SAM rule and I want to add it here.
Any help is appreciated. I am still looking but that first question has me concerned.