Solved: Optimizing an IPS profile for SMB - Check Point CheckMates

Optimizing an IPS profile for SMB

Policy install on SMB appliances can fail if the IPS configuration enables too many protections. According to CP, SMB devices were never designed to run a full IPS policy and it is suggested to check sk105217 "Commit function failed"/"Installation failed" error on policy installation failure on sma... for configuration suggestions:

.bmp)

In R80.x you can add categories to Profile > IPS > Additional Activation > Protections to deactivate list:

.bmp)

If this adaptions do not resolve the policy install issue, you can consult sk117793 Policy installation / fetch fails on Centrally Managed 1400 appliance  and sk126372 Policy installation on SMB appliances fails with "Load on Module failed - not enough disc s....

Please note that this is my own configuration that has not been checked by CheckPoint - and is open for discussions, corrections and additions. Also see this list SMB documents for more.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

5\ \ \ Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

1 Solution

Accepted Solutions

G_W_Albrecht

MVP Silver

‎2018-09-0606:48 AM

Show option menu

Jump to solution

This has been resolved by following this procedure:

- Cleared directories $FWDIR/state/__tmp/FW1, $FWDIR/database/cpeps_flash/ and $FWDIR/database/cpeps/

- enable only FW blade on SMB device object

- install policy

- enable TP blades on SMB object again

- install policy

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

View solution in original post

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

24 Replies

HristoGrigorov

MVP Gold

‎2018-05-3007:55 PM

Show option menu

Jump to solution

Is it possible to exclude all but certain protocols from IPS ? For example if I want only HTTP(S), DNS and SMTP inspected.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-06-0205:16 AM

Show option menu

Jump to solution

As stated above, you can deactivate IPS for protocols not needing inspection.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2018-06-0208:00 AM

Show option menu

Jump to solution

You do want me to go and exclude all protocol one by one. Ugh, that's what I want to avoid?

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

PhoneBoy

Admin

‎2018-06-0210:42 PM

Show option menu

Jump to solution

IPS only inspects traffic allowed by your access policy.

If you only allow HTTPS, DNS, and SMTP via your access policy, IPS will only inspect that traffic.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2018-06-0310:23 AM

Show option menu

Jump to solution

Thanx for the clarification. That is somehow logical but I am being paranoid lately

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Rodney_Hopkins2

Contributor

‎2018-09-0106:49 AM

Show option menu

Jump to solution

This is absolutely true.  I would add one additional piece of information.  In my experience with 1100 devices, the recommendation to disable protections earlier than 2010 was not enough.  As the years progressed, I had to disable protections from later years as well.  For example, in 2014, disabling protections older than 2010 worked.  By 2015, I had to disable protections older than 2012.  2016, disable protections older than 2013 and so on.  For the 1100 series at least, it worked out to roughly a window of 3 to 5 years of IPS protections that I could have enabled at any given time.

The newer 1400 series have more RAM and are more powerful, so they may be able to handle more.

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-09-0407:44 AM

Show option menu

Jump to solution

Just recently, i discovered that after firmware update to R77.20.80, on a 1140 SMB appliance policy install will fail as there are too many enabled blades, that is FW, VPN, IPS, ABOT, AV, APCL, URLF, QoS. Even setting new .80 Advanced Settings "Move temporary policy files to storage" to true does not help. That is a bad sign for a hardware that is supported until summer 2020...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2018-09-0408:16 PM

Show option menu

Jump to solution

Yeah, hmm... It is now evident that SMB appliances are just not up to task of being full FW + TP solution. It is good that there are so many blades to choose from but running all of them at the same time is overkill even on 1470/1490.  I have enabled only the AC/UF and IPS blades. Works somehow but SFWD process crashes way to often (max rss increased to 300MB). I understood there are other people experiencing same problem.

Would love to enable HTTPS inspection also. But I am kind of afraid to do it

And I wonder what it will be when/if R80.20 is released.

For me, stability is more important than anything else.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-09-0411:53 PM

Show option menu

Jump to solution

You have to think of SMB appliances as successors to the Edge / Safe@Office units - and in comparison, they have a whole lot more functionality - apart from NGTP, just look into the advanced routing possible now. But that enabling NGTP Blades lowers the traffic throughput is clear, and you can not argue that buying the blades and services makes the hardware able to cope with them performance-wise. More expensive hardware makes more ressources available, it would be unnecessarys otherwise 😉

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Rodney_Hopkins2

Contributor

‎2018-09-0501:02 PM

Show option menu

Jump to solution

Have you hit upon the magic combination or magic number of blades that can be enabled at once?

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-09-0511:56 PM

Show option menu

Jump to solution

No, because that also depends very much on the traffic, both its load and mix that can be quite different at every customer.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-09-0606:48 AM

Show option menu

Jump to solution

This has been resolved by following this procedure:

- Cleared directories $FWDIR/state/__tmp/FW1, $FWDIR/database/cpeps_flash/ and $FWDIR/database/cpeps/

- enable only FW blade on SMB device object

- install policy

- enable TP blades on SMB object again

- install policy

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Pedro_Espindola

Employee

‎2018-09-0607:57 AM

Show option menu

Jump to solution

Hello Hristo,

In the beginning I had some issues with HTTPS Inspection, but I worked with TAC and R&D was able to reach a stable build, I believe starting from build 402. GA is 392, but build 437 is available for download in sk134253 and also corrects some CVEs and VPN issues.

I am currently running HTTPS Inspection and full NGTP in a 1450 cluster with 12 users, 3 Site-to-site VPN Tunnels, 200 Mbps link. It is working fine.

There were some serious memory leak issues in SFWD but they seem to be solved as well. It has been weeks without a failover due to SFWD crash.

I believe we will see greater improvements in R77.20.85 also, which should be out in October.

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2018-09-0608:20 PM

Show option menu

Jump to solution

Hey Pedro,

I am running cluster of two 1470 appliances used by 70 users, 5 SS VPNs, few remote access users on a dual ISP connection with total 100 Mbps capacity. Not too much I think. Build is also 437.

Some days it will work fine, no issues. But on most of the days SFWD will crash every now and then. It is immediately restarted by a watchdog service and there is no failover in the cluster. In fact the only visible effect is that all SS VPNs are restarted (currently open user connections are dropped).  I have no other custom settings on the device other than the RSS memory increased to 300MB. R77.20.75 build 239 was the last one that had stable SFWD process that never crashed.

SecureXL does not work also for me. When I enabled it device restarts in few minutes. TAC was able to fix that and provide me with custom build but I had to replace it with 437 because of the CVE security fixes. I hope they will include this fix in the main branch.

HTTPS Inspection generally works here but I have disabled it because of the SNI problem that seems to be properly fixed only in R80.10 so far. Check this thread:

https://community.checkpoint.com/thread/6245-is-there-any-workaround-for-sni-https-traffic-when-enab...

I hope stability will be improved even more but as we discussed in another thread current Gaia embedded design is not very good (everything is handled by a single process). I am assuming this and other things will change in R80.20 if it is still planned release for SMB.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-09-1402:07 AM

Show option menu

Jump to solution

You wrote:

I would expect that a much smaller hardware footprint exists on this kind of embedded devices and that everything is handled by a single process is only a symptom of a reduction process. I do not expect these things to change in the future - if the hardware platform gets more power ( see the difference between 600/1100 and 7x0/14x0 models ), more functionality can be added. But in the same time, the "big" GAiA devices also get better hardware that makes new functionality possible. So the SMB devices will always keep behind and no full R80.20 port could ever be released for install on SMB. I do remember the older SMB units being included in turbines to provide them safe internet connectivity. 1200Rs are just looking richt for this field of application.

Next Version is R77.20.81, and a little bird has told me that it might bring more flexible ISP connections (more than four).

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2018-09-1402:15 AM

Show option menu

Jump to solution

Hi,

This is all too exciting but sadly SecureXL does not really work on SMB if you have ISP in load-balancing configuration. On primary/backup it works fine. I hope they fix that as well.

Reference sk104679

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-09-1402:54 AM

Show option menu

Jump to solution

The sk104679 does speak about ISP Redundancy enabled in Primary/Backup mode, and it also includes SMB as well as all CP versions up to R77.30. The configuration of ISPs in load-balancing configuration does not work with SecureXL at all despite of hotfixes installed. I would not expect that this can be fixed for SMBs...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2018-09-1403:00 AM

Show option menu

Jump to solution

Why would LB cause more load than HA? Btw, it is more like load sharing, not really balancing.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-09-1403:04 AM

Show option menu

Jump to solution

HA only has to check if the primary is up, but LS has to distribute the load according to some algorithm or config between the ISPs. This is similar ti the use of multiple cores as distributing work there also needs ressources...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2018-09-1403:11 AM

Show option menu

Jump to solution

Correct me if I am wrong but LB only works on outbound connections? Also, I do not think link selection algorithm is that complex to cause any significant load. It all depends on how many concurrent connections there are of course but still... Do not underestimate SMB power

Also, If it cannot LB between 2x ISP links why on earth would I need 4x ? One primary and three backups sounds crazy to me.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-09-1403:28 AM

Show option menu

Jump to solution

You can use SecureXL together with ISP redundancy (let us use the correct term). but not when ISP LB is needed - but what is the gain of using SecureXL on SMBs ? LB surely works on outbound connections as you rarely can control inbound connections.

The question of link selection algorithm is a rather complicated theme especially if the ISPs have different performance characteristics. Dpending on hard- and software, adding a second core might give 30% to 70% improvement (maybe even up tp 90%, but Amdahl's law rules).

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2018-09-1403:55 AM

Show option menu

Jump to solution

Hmm, isn't SecureXL supposed to offload some traffic from firewall module thus reducing actual load on the system? Something especially needed on these low-end devices.

I believe link selection on SMB is pure round-robin algorithm. I seriously doubt it is accounting for latency and such.... or keeping in time stats and trying to use some predictive methods... May be utilizing some fast math to prioritize link based on pre-configured preference.

I would vote for adding more memory and disk space rather than increasing number of cores but this is purely personal preference

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2018-09-1403:59 AM

Show option menu

Jump to solution

Now, look at this. Beautiful isn't it?

[cpWatchDog 2162 1744208784]@RD6281[13 Sep 12:41:03] [INFO] CPWD is already performing active monitoring on CheckPoint services/processes

[cpWatchDog 2162 1744208784]@RD6281[13 Sep 12:41:04] [SUCCESS] cposd started successfully (pid=2814)

[cpWatchDog 2162 1744208784]@RD6281[13 Sep 12:41:04] [SUCCESS] RTDB started successfully (pid=2834)

[cpWatchDog 2162 1744208784]@RD6281[13 Sep 12:42:38] [SUCCESS] SFWD started successfully (pid=5397)

[cpWatchDog 2162 1744208784]@RD6281[13 Sep 12:42:43] [SUCCESS] CPHAMCSET started successfully (pid=6707)

[cpWatchDog 2162 1744208784]@RD6281[14 Sep 9:03:11] [ERROR] Process SFWD terminated abnormally : Unhandled signal 6 (). Core dumped.

[cpWatchDog 2162 1744208784]@RD6281[14 Sep 9:04:11] [SUCCESS] SFWD started successfully (pid=21999)

[cpWatchDog 2162 1744208784]@RD6281[14 Sep 11:32:19] [ERROR] Process SFWD terminated abnormally : Unhandled signal 6 (). Core dumped.

[cpWatchDog 2162 1744208784]@RD6281[14 Sep 11:33:19] [SUCCESS] SFWD started successfully (pid=28000)

[cpWatchDog 2162 1744208784]@RD6281[14 Sep 13:40:58] [ERROR] Process SFWD terminated abnormally : Unhandled signal 11 (SIGSEGV). Core dumped.

[cpWatchDog 2162 1744208784]@RD6281[14 Sep 13:41:58] [SUCCESS] SFWD started successfully (pid=30460)

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2018-09-1404:13 AM

Show option menu

Jump to solution

This is a completely different theme, so please post that seperately from Optimizing an IPS profile for SMB

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

User Count

sx8n20394
7

israelfds95
7

jorgeluiznim
5

velo
1

BikeMan
1

emmap
1

CEEJAY
1

Max_Leorne
1

Chris_Atkinson
1

View All ≫

Trending Discussions

Reach My Device – A Native Option for Secure Remote Access to Quantum Spark Appliances

Downgrading a Quantum Spark Appliance: From 'Upgrade Not Supported' to a Working Boot Loader Recover

L2TP Remote Access VPN - Can't Connect on SMB 2550 R82.00.10

Upcoming Events

Sort by:

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Thu 30 Jul 2026 @ 11:30 AM (CDT)

CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Virtual

Thu 30 Jul 2026 @ 10:00 AM (PDT)

AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway

In-Person

Tue 11 Aug 2026 @ 11:30 AM (EDT)

New York City: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 13 Aug 2026 @ 11:30 AM (EDT)

Waltham, MA: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 20 Aug 2026 @ 08:30 AM (COT)

Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA

In-Person

Thu 20 Aug 2026 @ 06:00 PM (COT)

Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad

In-Person

Thu 27 Aug 2026 @ 09:00 AM (CEST)

Check Point Hands-On SASE and Cloud Workshop - Zurich

In-Person

Wed 21 Oct 2026 @ 09:00 AM (BST)

AI Security Workshop - Glasgow

CheckMates Events

Top

About CheckMates

Learn Check Point

Advanced Learning

Resources

Non-English Discussions

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.