> Source: [sk180863](https://support.checkpoint.com/results/sk/sk180863)

# sk180863 - Security Gateway generates a log that the "FTP Bounce" protection works in the "Detect" mode, although it is configured to work in the "Prevent" mode

| Property | Value |
|----------|-------|
| Solution ID | sk180863 |
| Date Created | 2023-05-21 |
| Last Modified | 2023-05-22 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- Although the IPS protection "FTP Bounce" is configured to work in the "Prevent" mode and the IPS Software Blade is configured to work "According to policy", the Security Gateway generates a log that the "FTP Bounce" protection works in the "Detect" mode.

## Cause

To prevent attacks on the FTP, such as FTP Bounce, the Security Gateway:

1. Changes the FTP packets when it inspects the FTP traffic and passes it through.
2. Uses the Stateful Inspection to validate the FTP traffic, which works faster and consumes less resources than the Threat Prevention inspection.
As a result, the Security Gateway generates the log that it used the applicable IPS protection in the "Detect" mode.

## Solution

No fix is required. This behavior is by design.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
