Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Adnan_Saleem
Participant

DNS trap

We have been getting LOT of alerts from our SIEM about Checkpoint IPS/Anti-Bot considering fastly.net domain as malicious and preventing it! We initially quarantined 200 assets before we could find in forensics that the Resource is fastly.net. Which is a false positive! Checkpoint support confirmed this too. Wondering how many pissed off today with these alerts?

(2)
11 Replies
Patrick_Taphorn
Participant

This false positive for fastly.net hit us too.   Glad to hear Checkpoint Support actually confirmed this was indeed a false positive.   Had some angry end-users here.

VikingsFan
Collaborator

We were seeing similar today.  Thanks for confirming with support.

the_rock
Legend
Legend

Thanks for sharing.

Andy

0 Kudos
PhoneBoy
Admin
Admin

False positives should always be reported to TAC, which it appears a few people did in this case.

Daniel_Kavan
Advisor

Rather than having to go thru submitting a case, maybe we could have a community share page where we can check in TO SPEED UP THE PROCESS and get the word out.   This is great as it is though.  I certainly had major heat yesterday for this.   Is it safe to turn DNS trap back on?

0 Kudos
the_rock
Legend
Legend

Good idea.

0 Kudos
VikingsFan
Collaborator

Our alerts stopped around 6PM EST yesterday.

0 Kudos
PhoneBoy
Admin
Admin

Reporting the issue in the community as was done in this and other similar cases helps get the word out.
Unfortunately, we do not have a more formal place to track this short of individual SK articles for specific "false positive" events.
The TAC case is to ensure the problem is properly tracked and resolved.

0 Kudos
VikingsFan
Collaborator

Is this something that Check Point would typically send a notification out to customers?  If so, how do I get on that mailing list?

0 Kudos
John-Haynes
Participant

I went to look into the same issue yesterday, but otx.alienvault.com was getting blocked as Glupteba.TC.804cfguz 😞

0 Kudos
the_rock
Legend
Legend

I just literally realized it was same issue I dealt with the client yesterday when you said the name Glupteba. Glad to know it was known issue, but yes, raised false amarms.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events