I am seeing some strange things in an R82 build 777 Threat Prevention Profile.
In a cloned Profile (cloned from Strict) I enabled Activate IPS protections according to the following additional properties, and then added the following to the Protections to activate:
Category > Vulnerability Type > SQL Injection and Injection
I do not have populated with any categories.
When I check IPS Protections and filter for SQL Injection is see that is actually deactivated 4 SQL Injection protections.
When I compare the Strict and the cloned profile columns I see 8 protections disabled in the cloned profile but only 4 in disabled in the Strict profile.
The General Policy is the same in the two profiles.
Anyone seen this before, or can anyone explain?
Reference:
https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/...