CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-06
Junior Member
 
Join Date: 2007-08-03
Posts: 13
Rep Power: 0
futureechos has an average reputation (10+)
Default Smart Defense Subscription

We've been running our Firewalls for about a year and seen a few problems where Smart Defense can be a little over zealous. We don't have a subscription to update SD at the moment, we're considering renewing with it.

If we do, and we get all the latest SD updates should we expect problems, I'm thinking of putting most of the features in monitor only to start with.

Anyone have any experience of this?

Any tips?


Thanks
FE
Reply With Quote
  #2 (permalink)  
Old 2007-12-06
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Smart Defense Subscription

In general before turning on then as you are looking too, then put the defense into monitor mode so it will apply anf log what would have dropped but not actually drop it.

That way you can see if going to cause you problems.

Leave in monitor for at least a month.
Reply With Quote
  #3 (permalink)  
Old 2007-12-06
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Smart Defense Subscription

A lot of SMDF has been "Fixed" but monitor mode is your friend.
I do find SMDF blocks a lot of junk hitting my network. Its really good at keeping all the IIS attacks away from my Apache servers.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:39.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0