- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have a WAF (Web Application Firewall) acting as external protection for our internally hosted web servers.
We also have a vulnerability scanner external to our network probing for issues which are generating a large number of IPS alerts.
When I look at the logs, the source IP field is the WAF internal address, and the 'Proxied Source IP' field contains the source IP of the external scanner.
I need to be able to create an exception for these IPS alerts, but there doesn't seem to be a way to specify the proxied source IP field in the exception, you can only seem to use the internal address of the WAF. I can't use this as it would blind us to probes from other external IP's that were getting through the WAF for some reason.
Is there a way to achieve the IPS exception for a specific proxied source IP?
Thx.
@G- that's not possible. There was a similar post IPS exception based on Proxied Source IP? - Check Point CheckMates
maybe @Timothy_Hall idea could work.
@G- that's not possible. There was a similar post IPS exception based on Proxied Source IP? - Check Point CheckMates
maybe @Timothy_Hall idea could work.
Thanks for the response. I tried searching but obviously missed that one. I'll have a look at the idea proposed. Cheers.
You also might be able to create a custom Snort IPS rule matching the proxy HTTP header field, import it, then create an exception matching that custom Snort rule with an action of Inactive.
Thanks for the additional idea Timothy. To be honest, I doubt I have enough time to learn how to do all that, I'm going to lean on the WAF supplier to create a unique SNAT for the external scanner and 'cheat' 🙂
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY