Detect and Prevent difference - Check Point CheckMates

Detect and Prevent difference

In SmartView, when CheckPoint shows Attacks (for example 2 critical attacks), If I click it (let's say it is found by Anti-Virus blade), it shows details and writes only "Action: Detect" and  "not prevented by policy".

Besides, in General Overview tab, it shows general information about detection and prevention (%).

How can I clearly understand them?

Does it mean that blades cannot prevent all type of attacks?

What is the difference between detect and prevent? Does "detect" refers to some kind of protection?

a1.jpg

Preview file

36 KB

a2.jpg

Preview file

36 KB

2\ \ \ Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

6 Replies

Daniel_Taney

Advisor

‎2018-07-0307:05 AM

Show option menu

If attacks are being logged as "Detect" it is because the Threat Prevention policy has not been set to "Prevent" those particular signatures. Based on the "a1.jpg" screen shot, it looks like your policy is in detect mode. Detect mode will just log + alert you to an event happening, but the Gateway won't actually prevent anything from happening. This mode is good to give you an idea what is going on in your environment.

However, if you want the Gateway to prevent things, those policies need to be changed over to "Prevent". In R80.10, you can do this by going to Security Policies -> Threat Prevention -> Policy and reviewing the settings. Check Point offers some "out of the box" templates like Strict, Optimized, and Basic to get you started. If you aren't totally familiar with Threat Prevention, one of these templates may be a good place to start.

R80 CCSA / CCSE

3\ \ \ Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

(1)

Reply

Network_M

Collaborator

‎2018-07-0309:31 PM

Show option menu

In response to Daniel_Taney

Is it dangerous for my network if it keeps going on in detect mode?

Or should I change it to prevent mode?

I'm not totally familiar with Threat Prevention and I don't know how to exactly turn on prevent mode.

I will check that templates, thanks.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Tomer_Sole

Mentor

‎2018-07-0710:24 PM

Show option menu

In response to Network_M

Yes, Detect is basically a temporary mode until the administrator makes a verdict to completely block the attack or disable a false-positive inspection. Sometimes doing full prevent + adding exceptions for certain internal traffic with "disable" is also acceptable.

The log card has various "go-to" links that let you change the configuration from there. Make sure to install policy to apply the change.

Compliance Blade will present a list of action items related to Threat Prevention. Some of them advise to switch from "detect-only" mode to "according to the policy".

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Network_M

Collaborator

‎2018-07-0905:49 AM

Show option menu

In response to Tomer_Sole

Which point I can start from?

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

PhoneBoy

Admin

‎2018-07-1303:47 AM

Show option menu

In response to Network_M

From one of the default policies as noted above.

For most customers, we recommend using the Optimized profile.

If you're new, you might want to review this TechTalk we did:

TechTalk: Advanced Threat Prevention Best Practices ‌

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Diego_Crispin

Explorer

‎2020-02-1901:58 PM

Show option menu

t detects and validates if it is malicious, if it is not, let it pass and be for malicious it blocked?

does it detect and prevent any action you take with this subscription service?

it inhibits the service, scam tools will no longer be able to view active service?

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

User Count

WiliRGasparetto
50

israelfds95
33

jorgeluiznim
14

Bob_Zimmerman
10

Martijn
8

Alex-
6

Tomer_Noy
6

Lesley
5

emmap
5

simonemantovani
5

View All ≫

Trending Discussions

Bug on LOM Date and Time

[TIP] Check Point Migration Backup: Collecting Relevant Files Before a Clean Install

[INFO] Why Can Gaia Configure LOM If LOM Is Supposed to Be Independent?

Upcoming Events

Sort by:

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Thu 30 Jul 2026 @ 11:30 AM (CDT)

CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Virtual

Thu 30 Jul 2026 @ 10:00 AM (PDT)

AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway

In-Person

Tue 11 Aug 2026 @ 11:30 AM (EDT)

New York City: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 13 Aug 2026 @ 11:30 AM (EDT)

Waltham, MA: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 20 Aug 2026 @ 08:30 AM (COT)

Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA

In-Person

Thu 20 Aug 2026 @ 06:00 PM (COT)

Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad

In-Person

Thu 27 Aug 2026 @ 09:00 AM (CEST)

Check Point Hands-On SASE and Cloud Workshop - Zurich

In-Person

Wed 21 Oct 2026 @ 09:00 AM (BST)

AI Security Workshop - Glasgow

CheckMates Events

Top

About CheckMates

Learn Check Point

Advanced Learning

Resources

Non-English Discussions

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.