CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Monitor/SmartView Status
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-11
Senior Member
 
Join Date: 2006-02-18
Posts: 103
Rep Power: 3
ChrisA has an average reputation (10+)
Default Suspicious Activity Rules - utilization concerns?

Do suspicious activity rules bog down the system?

We're running R62, distributed environment. SmartCenter Server is SPLat; gateways are clustered Nokias.

We have a proxy server on our internal network that has more outbound access than desired, and we're pruning out the access that's definitely not needed (drop rules in SmartDashboard). For access that is questionable, I'd like to implement a couple of suspicious activity rules in SmartView Monitor, dropping and logging the sessions that we're not sure are needed. We cannot install policies during the day; they have to be scheduled a day in advance and can only be done after hours, so I need a way to open the access back up without installing a policy, if we discover the access is required for business purposes.

Does this sound like a good method? Any concerns/gotchas? Thanks All!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 08:04.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0