> Source: [sk177063](https://support.checkpoint.com/results/sk/sk177063)

# sk177063 - Exceptions for IPS protections have limited functionality for some protections on Locally Managed Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk177063 |
| Date Created | 2022-01-09 |
| Last Modified | 2024-05-20 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1500, 1600, 1800 |

## Symptoms

- Exceptions for some specific IPS protections may not function as configured.

## Cause

On locally managed Quantum Spark appliances, IPS protections that belong to "Core IPS protections" and "Inspection Setting" protection groups (see the full list below) are configured through general "Threat Prevention Exceptions" control. Not all of the available features are supported.

### Limitations:

* "Any IPS" exception is not applied.
* "Action" configuration property has no effect - default behavior is "Inactive."
* "Log" configuration property has no effect - default behavior is "None."
* Updatable objects and FQDN are not supported as source or destination
* "URLs Allowlist" is not supported.
* "Files (md5sum) Allowlist" is not supported.

### Full list:

|---------------------------------------|--------------------------------------------------|------------------------------------------|
| LAND                                  | Maximum SMTP Command Line Length Enforcement     | Empty IMAP Password                      |
| Small PMTU                            | Maximum SMTP Commands Per Connection Enforcement | Empty IMAP Username                      |
| Port Overflow                         | Minimum Command Line Length Enforcement          | Non Compliant IMAP                       |
| Max Ping Size                         | Maximum No-Effect Commands Enforcement           | IMAP STARTTLS Command                    |
| Non-TCP Flooding                      | Maximum Number of Recipients Enforcement         | SNMP                                     |
| Network Quota                         | Maximum Empty Commands Enforcement               | Samba Long CIFS Passwords Buffer overrun |
| Dynamic Ports                         | Use Malicious Code Protector for SMTP            | Microsoft Windows NT Null CIFS Sessions  |
| Domains Block List                    | Microsoft Exchange Server Commands               | Non Compliant CIFS                       |
| Inbound DNS Request                   | SMTP Private Commands                            | LDAP Injection                           |
| Mismatched Replies                    | SMTP Recipients with No Domain Name              | Command Injection                        |
| Scrambling                            | Non Compliant SMTP                               | HTTP Format Sizes                        |
| Non Compliant DNS                     | Bad SMTP Server Greeting                         | Cross-Site Scripting                     |
| Unknown Resource Record               | SMTP STARTTLS Command                            | HTTP Methods                             |
| DNS Data Overflow                     | Unknown SMTP Commands                            | SQL Injection                            |
| DNS Maximum Request Length            | Maximum Bad POP3 Commands Enforcement            | Directory Traversal                      |
| DNS Maximum Reply Length              | Maximum POP3 Command Line Length Enforcement     | Malicious Code Protector                 |
| DNS Reserved Header Bit               | Maximum POP3 Commands Per Connection Enforcement | Header Spoofing                          |
| FTP Bounce                            | Use Malicious Code Protector for POP3            | Directory Listing                        |
| Unauthorized Application              | Empty POP3 Password                              | Error Concealment                        |
| Citrix ICA Protocol Enforcement       | Empty POP3 Username                              | ASCII Only Request                       |
| Binary Data In SMTP Commands          | Non Compliant POP3                               | ASCII Only Response Headers              |
| Maximum Bad SMTP Commands Enforcement | POP3 STARTTLS Command                            | Packet Sanity                            |

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
