Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Rabin
Explorer
Jump to solution

Threat Prevention logs

Hi Checkmates,

Wanted to know why my customize threat policies does not get hit, if my global exception policies is in detect mode. Do we need to set global exception policies to set at prevent mode to prevent attack or do we have to disable the global exception to get hit on customize threat policies.

Thank You.

Rabindra

0 Kudos
1 Solution

Accepted Solutions
Tal_Paz-Fridman
Employee
Employee

In general there many SKs and administration guides to help with this. For example:

Threat Prevention R81.20 Best Practices

https://sc1.checkpoint.com/documents/Best_Practices/CP_R81.20_Best_Practices_for_Threat_Prevention/C...

 

https://support.checkpoint.com/results/sk/sk167102

 

One less "global" option would be to start without exceptions but to use the Threat Prevention Profile in Detect or Prevent Mode (depending on how aggressive you want the protections to be) and then start analyzing the logs and adding exclusions directly from log.

From there you might want to start adding Global Exceptions again Detect or Prevent and change after a while.

 

Add Exception 1.pngAdd Exception 2.png

View solution in original post

0 Kudos
1 Reply
Tal_Paz-Fridman
Employee
Employee

In general there many SKs and administration guides to help with this. For example:

Threat Prevention R81.20 Best Practices

https://sc1.checkpoint.com/documents/Best_Practices/CP_R81.20_Best_Practices_for_Threat_Prevention/C...

 

https://support.checkpoint.com/results/sk/sk167102

 

One less "global" option would be to start without exceptions but to use the Threat Prevention Profile in Detect or Prevent Mode (depending on how aggressive you want the protections to be) and then start analyzing the logs and adding exclusions directly from log.

From there you might want to start adding Global Exceptions again Detect or Prevent and change after a while.

 

Add Exception 1.pngAdd Exception 2.png

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events