- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello guys!
I prepared a SNORT rule to drop DoS tools patterns like traffic, the rule is working fine, can you tell after how much time will the FW send the IP's attacking the network after matching the rule?
Or is there a way to put in the snort rule a way like send to sam or not?
Because I know that for snort there is snortsam a plugin for snort:
Is there any kind of plugin or feature for the R77.30 FW/IPS?
Thank you vey much in advance.
You should be able to use one of the User Defined log settings for the protection to trigger a script to do whatever you want.
See the screenshot below.

Just to clarify your question:
Correct?
Hi Dameon!
First of all thank you for your reply.
And that's that, I want it to automatically block the IP.
Thank you.
I will check with R&D, but I do not believe this is possible out of the box.
It may be possible by monitoring logs and using that to trigger an fw sam/fw samp command to issue a block.
Hey,
Would you mind share that snort rule with me? Let me try with some bash script and see if that works.
You should be able to use one of the User Defined log settings for the protection to trigger a script to do whatever you want.
See the screenshot below.

Does some one know if customer rules (for example based on Snort) will be possible out of the box in the future?
It can already be done as far as I know.
The above screenshot is individual to a specific protection.
Dameon, you are right. Here is the relevant chapter in the admin guide:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY