Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Dynamic block rules for IPS events

From Tech-Wiki


Use a Check Point IPS user-defined alert action to create a temporary SAM block for the source address that triggered an IPS event.

ⓘ
Example behaviour
The example retained from the original article creates an automatic SAM rule for one hour using the source IP address associated with the IPS event.

SAM action

sam_alert -t 3600 -I -src

Configure the IPS protection

In SmartDashboard:

  1. Open the IPS tab and select Protections.
  2. Search for Host Port Scan.
  3. Open the protection.
  4. Open the relevant IPS profile assigned to the Security Gateway.
  5. Select Override IPS Policy with and choose Detect.
  6. In Track, select User Defined Alert no. 1.
  7. Set the required detection sensitivity.
  8. Apply the changes.

Configure the automatic SAM rule

  1. Open Policy → Global Properties.
  2. Expand Log and Alerts and select Alerts.
  3. Enable Run UserDefined script under Send user defined alert no.1 to SmartView Monitor.
  4. Configure the SAM command:
sam_alert -t 3600 -I -src
!
This dynamically blocks the detected source
Test the rule and alert conditions carefully to avoid automatically blocking legitimate hosts because of a false-positive IPS event.

See also