- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
by default sam_alert install in all the firewalls.
How could I exclude same firewall or clusters?
Or how could I include only specific firewalls or clusters? What is the syntax to install it in a list of fw/clusters?
https://support.checkpoint.com/results/sk/sk110873
would something like this work?
sam_alert -f gw1, gw2
sam_alert -f cluster1, cluster2
From what I know, syntax doesn't support 2 targets. You need to run it multiple times if you want different GWs to have it.
You can also do "dry runs" and look at "SmartView Monitor" to see the policy:
It works, but only 1 gw is possible in the command.
Andy
so If I can't configure multiple targets, could I disable SAM in certain gateways? So when I run the default install in all, it only gets installed in the gateways I want. How?
You mean disable ability to create sam rule on specific gateway?
yes
I will need to look at documentation and experiment in my lab to provide an answer to that. Will try to get to it when I can.
WA I suggest is using script with desired GWs in a list and instead of using regular commands and let the script go over it.
would something like this at <global properties - log and alert - alerts - run userdefined script> work?
sam_alert -t 600 -I -src -f cluster1; sam_alert -t 600 -I -src -f cluster2
Interesting idea...let me see if I can test it in the lab.
I have tested it and it doesn't work.
Now in terms of the script, I have read recommendation to run the script on path $FWDIR/bin. The problem with that path is that we will need to copy the script the new $FWDIR/bin everytime we do an upgrade, right? Is there any other path that will survive an upgrade?
I also have the impression that sam_alert reads a line of stdin and then goes to the next, so it is not possible to run to sam_alert with the same ip address to block and two different clusters.
$FWDIR/bin
script.sh
#!/bin/bash
sam_alert -t 600 -I -src -f cluster1
sam_alert -t 600 -I -src -f cluster2
chmod 755 script.sh
For sure, script would need to be copied, as its not built in.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY