Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Don_Paterson
MVP Gold
MVP Gold

Threat Prevention Profile strange behaviour - Activate IPS protections according to the following...

I am seeing some strange things in an R82 build 777 Threat Prevention Profile.

 

In a cloned Profile (cloned from Strict) I enabled Activate IPS protections according to the following additional properties, and then added the following to the Protections to activate:

Category > Vulnerability Type > SQL Injection and Injection

I do not have Protections to deactivate populated with any categories.

When I check IPS Protections and filter for SQL Injection is see that is actually deactivated 4 SQL Injection protections.

When I compare the Strict and the cloned profile columns I see 8 protections disabled in the cloned profile but only 4 in disabled in the Strict profile.

The General Policy is the same in the two profiles.

Anyone seen this before, or can anyone explain?

 

Reference:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/...

 

0 Kudos
3 Replies
Don_Paterson
MVP Gold
MVP Gold

I applied Take 39 and it looks the same.

The screenshot I captured was with the cloned profile selected. If I click on the Strict profile column to re-order it the behaviour (view) seems to be different to when I click the cloned profile column to change the ordering.

I wonder if I am missing something...

0 Kudos
the_rock
MVP Gold
MVP Gold

Im on latest jumbo 41,  looks okay to me.

0 Kudos
Don_Paterson
MVP Gold
MVP Gold

After looking into this again I see that the problem is that the 4 Protections that are Inactive are missing the tag Injection and/or SQL Injections.

Since Tags are assigned by RnD and cannot be edited on the customer side this will have to be fixed by RnD.

 

@PhoneBoy is this something you can bring to the IPS groups attention, please?

Details attached and my original message should make it clear.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events