IPS exception for pre R80 gateways with R80 SMS - Check Point CheckMates
IPS exception for pre R80 gateways with R80 SMS
Hello guys,
I have a question regarding the IPS exception possibilites for threat prevention profiles within a R80 SMS that is applied to pre R80 gateways. To be precise; the gateways in this case are running R76.50 (scalable platform release). As far as I've seen it is only possible to configure exceptions in the threat prevention exceptions tab - and here I realized that the action for any exceptions that need to be applied to pre R80 gateways is "inactive". But with that in place I am not able to see anything in my logs as IPS checking is just not done on the specific traffic described in the threat prevention exception rule. Now my question is - am I missing something or is there really no chance to configure "detect", so that IPS logs are still being received for the exception? I personally do not want to just ignore it in the first place. My plan is to have the SIEM team check whether its a false positive (during this time I want the detect option) and after confirming the false positive its fine for me to just set the action to "inactive".
Thanks in advance for any advices!
Best regards,
Maik
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
7 Replies
MVP Silver
2018-09-0511:44 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As the name already hints to, an IPS exception excludes traffic from IPS. IPS set to detect consumes the same ressources as when in protect mode, so it makes no sense to detect anything except in the first weeks of getting IPS into production.
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Advisor
2018-09-0511:53 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Günther,
Thanks for your reply. I understand IPS exceptions in the way that you have some kind of exclusion (differences) regarding the standard profile settings for specific traffic/signatures. Not in the way, that this automatically means you want to exclude such traffic completely from the IPS point of view.
That being said, I think it makes sense to detect something in this case as we are performing a restructure of the network (for some parts) and therefore need the detect just for specific sources, destinations & signatures. As these aren't that many hosts a new profile does not make much sense (which could have been another option).
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Silver
2018-09-0612:02 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You seem to understand IPS exceptions in a wrong way 😞 this is used for traffic that shall not be inspected at all by IPS (only very basic testing, e.g. Anti-Spoofing is performed in fw chain). If you need to detect traffic, use a special profile for this kind of traffic to make it work and log in detect mode.
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Advisor
2018-09-0612:52 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hm, I am wondering why there is the possibility for R80.x gateways to have the options of "inactive", "detect", "prevent" and "ask" within the exception action settings then. Nevertheless, thanks for the information regarding the impact on the fw chain and what is still done after specifying an exception - was not aware of that.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
MVP Silver
2018-09-0601:54 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The options of "inactive", "detect", "prevent" and "ask" within the exception action settings - I can not see that here:
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Advisor
2018-09-0602:52 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am talking about the exception policy settings right below the actual threat prevention policies within the SmartConsole. [The hosts and rule shown in the screenshot are based on a cloud demo session]
Edit: Am I missing something? If yes, what exactly?
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Admin
2018-09-0712:01 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This exception does not apply for pre-R80 gateways.
The exceptions you configure in the threat prevention exceptions tab are for excluding traffic from IPS entirely, not applying a different action to the traffic.
R80.x gateways have significantly more flexibility with regards to IPS profiles, exceptions, and so on.
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Post Reply
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
WiliRGasparetto |
50 |
israelfds95 |
33 |
jorgeluiznim |
14 |
Bob_Zimmerman |
10 |
Martijn |
8 |
Alex- |
6 |
Tomer_Noy |
6 |
Lesley |
5 |
emmap |
5 |
simonemantovani |
5 |
Trending Discussions
[TIP] Check Point Migration Backup: Collecting Relevant Files Before a Clean Install
[INFO] Why Can Gaia Configure LOM If LOM Is Supposed to Be Independent?
Upcoming Events
Sort by:
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats
Wed 29 Jul 2026 @ 12:00 PM (SGT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT
Wed 29 Jul 2026 @ 02:00 PM (IDT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER
Wed 29 Jul 2026 @ 03:00 PM (CEST)
The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 11:30 AM (CDT)
CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Wed 29 Jul 2026 @ 12:00 PM (SGT)
Wed 29 Jul 2026 @ 02:00 PM (IDT)
Wed 29 Jul 2026 @ 03:00 PM (CEST)
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway
Tue 11 Aug 2026 @ 11:30 AM (EDT)
New York City: Agentic AI Security Deep Dive & Hands-On
Thu 13 Aug 2026 @ 11:30 AM (EDT)
Waltham, MA: Agentic AI Security Deep Dive & Hands-On
Thu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA
Thu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad
Thu 27 Aug 2026 @ 09:00 AM (CEST)
Check Point Hands-On SASE and Cloud Workshop - Zurich
Wed 21 Oct 2026 @ 09:00 AM (BST)
AI Security Workshop - Glasgow
About CheckMates
Learn Check Point
Advanced Learning
Resources
Non-English Discussions
YOU DESERVE THE BEST SECURITY
We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram
©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.