- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello guys!
I prepared a SNORT rule to drop DoS tools patterns like traffic, the rule is working fine, can you tell after how much time will the FW send the IP's attacking the network after matching the rule?
Or is there a way to put in the snort rule a way like send to sam or not?
Because I know that for snort there is snortsam a plugin for snort:
Is there any kind of plugin or feature for the R77.30 FW/IPS?
Thank you vey much in advance.
You should be able to use one of the User Defined log settings for the protection to trigger a script to do whatever you want.
See the screenshot below.
Just to clarify your question:
Correct?
Hi Dameon!
First of all thank you for your reply.
And that's that, I want it to automatically block the IP.
Thank you.
I will check with R&D, but I do not believe this is possible out of the box.
It may be possible by monitoring logs and using that to trigger an fw sam/fw samp command to issue a block.
Hey,
Would you mind share that snort rule with me? Let me try with some bash script and see if that works.
You should be able to use one of the User Defined log settings for the protection to trigger a script to do whatever you want.
See the screenshot below.
Does some one know if customer rules (for example based on Snort) will be possible out of the box in the future?
It can already be done as far as I know.
The above screenshot is individual to a specific protection.
Dameon, you are right. Here is the relevant chapter in the admin guide:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
1 | |
1 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY