> Source: [sk117397](https://support.checkpoint.com/results/sk/sk117397)

# sk117397 - Global IPS Exception for "Any" protection does not work 

| Property | Value |
|----------|-------|
| Solution ID | sk117397 |
| Date Created | 2017-05-16 |
| Last Modified | 2019-11-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * **The below article provides solution for different scenarios when Global IPS Exception for "Any" protection does not work.
  Please see the below symptoms and follow the solution.**

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk117397/Exception1705161209.png)
* "`Unauthenticated MS-RPC traffic`" error for dropped DCE-RPC traffic on port 135.  
  When using Network Exception in IPS and using ANY in Protections, the exception does not work and we can see IPS logs for this traffic in SmartView Tracker.   

  Changing the ANY to a specific protection makes it work as it should and no more logs are seen in SmartView Tracker.   
  IPS exception does not work when the DCE-RPC connection is resumed and might not work for SMTP traffic.  

* Global IPS Exception for protection "Any" does not work for SMTP, IMAP and POP3 traffic when using IPS with Anti-Virus or another blade.  
  The IPS log shows that traffic from the globally excluded servers still hits these protections.   

* Traffic is dropped as "`Invalid Bind ACK message`" when IPS exception for protection "ANY" is configured.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
