Dynamic block rules for IPS events
From Tech-Wiki
More actions
Use a Check Point IPS user-defined alert action to create a temporary SAM block for the source address that triggered an IPS event.
Example behaviour
The example retained from the original article creates an automatic SAM rule for one hour using the source IP address associated with the IPS event.
SAM action
sam_alert -t 3600 -I -src
Configure the IPS protection
In SmartDashboard:
- Open the IPS tab and select Protections.
- Search for Host Port Scan.
- Open the protection.
- Open the relevant IPS profile assigned to the Security Gateway.
- Select Override IPS Policy with and choose Detect.
- In Track, select User Defined Alert no. 1.
- Set the required detection sensitivity.
- Apply the changes.
Configure the automatic SAM rule
- Open Policy → Global Properties.
- Expand Log and Alerts and select Alerts.
- Enable Run UserDefined script under Send user defined alert no.1 to SmartView Monitor.
- Configure the SAM command:
sam_alert -t 3600 -I -src
This dynamically blocks the detected source
Test the rule and alert conditions carefully to avoid automatically blocking legitimate hosts because of a false-positive IPS event.