- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
I am seeing some strange things in an R82 build 777 Threat Prevention Profile.
In a cloned Profile (cloned from Strict) I enabled Activate IPS protections according to the following additional properties, and then added the following to the Protections to activate:
Category > Vulnerability Type > SQL Injection and Injection
I do not have Protections to deactivate populated with any categories.
When I check IPS Protections and filter for SQL Injection is see that is actually deactivated 4 SQL Injection protections.
When I compare the Strict and the cloned profile columns I see 8 protections disabled in the cloned profile but only 4 in disabled in the Strict profile.
The General Policy is the same in the two profiles.
Anyone seen this before, or can anyone explain?
Reference:
The tag has been updated on the four protections on the backend and should appear in an IPS update in the next day or so.
Thank you sir!
Looks like the updates are out already.
I got the IPS Update email 3 hours ago (I recognised some of the protection names) and just checked in my lab and I can see the updates.
They are part of:
Package No. 635256924 |
I applied Take 39 and it looks the same.
The screenshot I captured was with the cloned profile selected. If I click on the Strict profile column to re-order it the behaviour (view) seems to be different to when I click the cloned profile column to change the ordering.
I wonder if I am missing something...
Im on latest jumbo 41, looks okay to me.
After looking into this again I see that the problem is that the 4 Protections that are Inactive are missing the tag Injection and/or SQL Injections.
Since Tags are assigned by RnD and cannot be edited on the customer side this will have to be fixed by RnD.
@PhoneBoy is this something you can bring to the IPS groups attention, please?
Details attached and my original message should make it clear.
Hey Don,
Did you end up fixing this?
Best,
Andy
Nope.
To me it seems like an issue with the product.
If you read my last note you will see that I identified that Tags are missing from some IPS ThreatCloud Protections.
Could be...
I'm pretty sure it is. Adding Tags to Protections is not something an admin can do, only RnD. They assign the tags for the purpose of use in the TP Profiles (exclusively)
@PhoneBoy will hopefully be able to bring it to the IPS groups' attention and have them clarify and/or fix.
Ah, got it. Once Im back in Canada, will test it in my lab, but I take your word for it Don (aka Steve).
Andy (LP)
The tag has been updated on the four protections on the backend and should appear in an IPS update in the next day or so.
Thank you sir!
Looks like the updates are out already.
I got the IPS Update email 3 hours ago (I recognised some of the protection names) and just checked in my lab and I can see the updates.
They are part of:
Package No. 635256924 |
Excellent, Don!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
1 | |
1 | |
1 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY