Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Don_Paterson
MVP Gold
MVP Gold

Threat Prevention Profile strange behaviour - Activate IPS protections according to the following...

I am seeing some strange things in an R82 build 777 Threat Prevention Profile.

 

In a cloned Profile (cloned from Strict) I enabled Activate IPS protections according to the following additional properties, and then added the following to the Protections to activate:

Category > Vulnerability Type > SQL Injection and Injection

I do not have Protections to deactivate populated with any categories.

When I check IPS Protections and filter for SQL Injection is see that is actually deactivated 4 SQL Injection protections.

When I compare the Strict and the cloned profile columns I see 8 protections disabled in the cloned profile but only 4 in disabled in the Strict profile.

The General Policy is the same in the two profiles.

Anyone seen this before, or can anyone explain?

 

Reference:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/...

 

0 Kudos
8 Replies
Don_Paterson
MVP Gold
MVP Gold

I applied Take 39 and it looks the same.

The screenshot I captured was with the cloned profile selected. If I click on the Strict profile column to re-order it the behaviour (view) seems to be different to when I click the cloned profile column to change the ordering.

I wonder if I am missing something...

0 Kudos
the_rock
MVP Gold
MVP Gold

Im on latest jumbo 41,  looks okay to me.

Best,
Andy
0 Kudos
Don_Paterson
MVP Gold
MVP Gold

After looking into this again I see that the problem is that the 4 Protections that are Inactive are missing the tag Injection and/or SQL Injections.

Since Tags are assigned by RnD and cannot be edited on the customer side this will have to be fixed by RnD.

 

@PhoneBoy is this something you can bring to the IPS groups attention, please?

Details attached and my original message should make it clear.

0 Kudos
the_rock
MVP Gold
MVP Gold

Hey Don,

Did you end up fixing this?

Best,

Andy

Best,
Andy
0 Kudos
Don_Paterson
MVP Gold
MVP Gold

Nope. 

To me it seems like an issue with the product. 

If you read my last note you will see that I identified that Tags are missing from some IPS ThreatCloud Protections. 

0 Kudos
the_rock
MVP Gold
MVP Gold

Could be...

Best,
Andy
0 Kudos
Don_Paterson
MVP Gold
MVP Gold

I'm pretty sure it is. Adding Tags to Protections is not something an admin can do, only RnD. They assign the tags for the purpose of use in the TP Profiles (exclusively)

@PhoneBoy will hopefully be able to bring it to the IPS groups' attention and have them clarify and/or fix.

0 Kudos
the_rock
MVP Gold
MVP Gold

Ah, got it. Once Im back in Canada, will test it in my lab, but I take your word for it Don (aka Steve).

Andy (LP)

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events