> Source: [sk182060](https://support.checkpoint.com/results/sk/sk182060)

# sk182060 - Protected Scope parameter in Threat Prevention rule does not apply the address range

| Property | Value |
|----------|-------|
| Solution ID | sk182060 |
| Date Created | 2024-02-28 |
| Last Modified | 2024-02-29 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- Although the Threat Prevention rule includes an address range in the Protected Scope parameter, the address range fails to match when there is inbound traffic, such as a bot from the internet attempting to connect with a host behind the Security Gateway. The network and host objects included in the Protected Scope parameter work correctly.

## Cause

The Anti-Bot engine is designed to operate in a Protected Scope, using the source IP address of the connection. The Anti-Bot engine focuses on connections initiated from inside the organization, targeting bots that establish connections to the internet.   

The issue described in the symptom above occurred because the address range in the rule contains the connection's destination rather than its source.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
