- Products
- Learn
- Local User Groups
- Partners
- More
The State of Ransomware Q1 2026
Key Trends and Their Impact
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
I am seeing some strange things in an R82 build 777 Threat Prevention Profile.
In a cloned Profile (cloned from Strict) I enabled Activate IPS protections according to the following additional properties, and then added the following to the Protections to activate:
Category > Vulnerability Type > SQL Injection and Injection
I do not have Protections to deactivate populated with any categories.
When I check IPS Protections and filter for SQL Injection is see that is actually deactivated 4 SQL Injection protections.
When I compare the Strict and the cloned profile columns I see 8 protections disabled in the cloned profile but only 4 in disabled in the Strict profile.
The General Policy is the same in the two profiles.
Anyone seen this before, or can anyone explain?
Reference:
The tag has been updated on the four protections on the backend and should appear in an IPS update in the next day or so.
Thank you sir!
Looks like the updates are out already.
I got the IPS Update email 3 hours ago (I recognised some of the protection names) and just checked in my lab and I can see the updates.
They are part of:
|
Package No. 635256924 |
I applied Take 39 and it looks the same.
The screenshot I captured was with the cloned profile selected. If I click on the Strict profile column to re-order it the behaviour (view) seems to be different to when I click the cloned profile column to change the ordering.
I wonder if I am missing something...
Im on latest jumbo 41, looks okay to me.
After looking into this again I see that the problem is that the 4 Protections that are Inactive are missing the tag Injection and/or SQL Injections.
Since Tags are assigned by RnD and cannot be edited on the customer side this will have to be fixed by RnD.
@PhoneBoy is this something you can bring to the IPS groups attention, please?
Details attached and my original message should make it clear.
Hey Don,
Did you end up fixing this?
Best,
Andy
Nope.
To me it seems like an issue with the product.
If you read my last note you will see that I identified that Tags are missing from some IPS ThreatCloud Protections.
Could be...
I'm pretty sure it is. Adding Tags to Protections is not something an admin can do, only RnD. They assign the tags for the purpose of use in the TP Profiles (exclusively)
@PhoneBoy will hopefully be able to bring it to the IPS groups' attention and have them clarify and/or fix.
Ah, got it. Once Im back in Canada, will test it in my lab, but I take your word for it Don (aka Steve).
Andy (LP)
The tag has been updated on the four protections on the backend and should appear in an IPS update in the next day or so.
Thank you sir!
Looks like the updates are out already.
I got the IPS Update email 3 hours ago (I recognised some of the protection names) and just checked in my lab and I can see the updates.
They are part of:
|
Package No. 635256924 |
Excellent, Don!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 33 | |
| 10 | |
| 10 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 6 | |
| 6 | |
| 6 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY