- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
by default sam_alert install in all the firewalls.
How could I exclude same firewall or clusters?
Or how could I include only specific firewalls or clusters? What is the syntax to install it in a list of fw/clusters?
https://support.checkpoint.com/results/sk/sk110873
would something like this work?
sam_alert -f gw1, gw2
sam_alert -f cluster1, cluster2
From what I know, syntax doesn't support 2 targets. You need to run it multiple times if you want different GWs to have it.
You can also do "dry runs" and look at "SmartView Monitor" to see the policy:
It works, but only 1 gw is possible in the command.
Andy
so If I can't configure multiple targets, could I disable SAM in certain gateways? So when I run the default install in all, it only gets installed in the gateways I want. How?
You mean disable ability to create sam rule on specific gateway?
yes
That Im not sure, sorry. Maybe @Amir_Senn can confirm.
Andy
I will need to look at documentation and experiment in my lab to provide an answer to that. Will try to get to it when I can.
WA I suggest is using script with desired GWs in a list and instead of using regular commands and let the script go over it.
would something like this at <global properties - log and alert - alerts - run userdefined script> work?
sam_alert -t 600 -I -src -f cluster1; sam_alert -t 600 -I -src -f cluster2
Interesting idea...let me see if I can test it in the lab.
I have tested it and it doesn't work.
Now in terms of the script, I have read recommendation to run the script on path $FWDIR/bin. The problem with that path is that we will need to copy the script the new $FWDIR/bin everytime we do an upgrade, right? Is there any other path that will survive an upgrade?
I also have the impression that sam_alert reads a line of stdin and then goes to the next, so it is not possible to run to sam_alert with the same ip address to block and two different clusters.
$FWDIR/bin
script.sh
#!/bin/bash
sam_alert -t 600 -I -src -f cluster1
sam_alert -t 600 -I -src -f cluster2
chmod 755 script.sh
For sure, script would need to be copied, as its not built in.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 65 | |
| 23 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 7 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY