CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-29
Senior Member
 
Join Date: 2006-02-18
Posts: 103
Rep Power: 3
ChrisA has an average reputation (10+)
Default Block GoToMyPC in Monitor Only mode - not tracking/logging

We're running R62. I set "Block GoToMyPC" to Active and checked Monitor Only mode. In SmartView Tracker I see "accept" entries. I expect the traffic to be allowed since I have monitor mode on, but shouldn't I see something in the Attack Name, Attack Info, or other columns to signify that SmartDefense "sees" the sessions and would block them if monitor only wasn't checked?
Reply With Quote
  #2 (permalink)  
Old 2007-06-29
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 291
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Block GoToMyPC in Monitor Only mode - not tracking/logging

I think it should actually show up in your logs as "M" (Smart Defense Monitor only) instead of accept. You can set this as a filter on the action column of tracker.

I am assuming that when you turned on monitor for this, you told it to log.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #3 (permalink)  
Old 2007-06-29
Senior Member
 
Join Date: 2006-02-18
Posts: 103
Rep Power: 3
ChrisA has an average reputation (10+)
Default Re: Block GoToMyPC in Monitor Only mode - not tracking/logging

SmartDefense settings for Block GoToMyPC:
Mode: Active is selected
Action: Monitor Only - no protection is checked
Track - Log is selected

In the SmartView Tracker, the entries in the log show Accept in the action column, nothing in the Attack Name or Attack Info columns, and "service_id: GoToMyPC" in the information column.

Might this be a bug or am I doing something wrong? Is there some other setting that must also be turned on?
Reply With Quote
  #4 (permalink)  
Old 2007-07-02
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 255
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Block GoToMyPC in Monitor Only mode - not tracking/logging

In pre-R65 versions it is known that in some cases 'Monitor only' will not just monitor the selected action. This is a known bug of SmartDefense. Upgrade to NGX (R65) or set to Allow.

Best regards,
Danny Trommer
CCSA/CCSE/CCSE+
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:22.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0