<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AIOps alerts and penalty box configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AIOps-alerts-and-penalty-box-configuration/m-p/276829#M105341</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;We recently enabled AIOps. We are now getting ferequenst alerts of the following type&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Rulebase drop spike caused by a burst of blocked traffic not a policy or gateway fault.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Rulebase drops rose sharply at 19:33Z and stayed very high for about 20 minutes with no policy change. This points to a burst of un&lt;SPAN data-teams="true"&gt;wanted traffic correctly blocked by existing rules not a gateway failure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Recommendations:&lt;/P&gt;
&lt;UL style="padding-left: 20px;"&gt;
&lt;LI&gt;Implement SecureXL-based DoS defenses including Rate Limiting rules and Penalty Box to block abusive traffic earlier. (sk112241)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We understand this is due to scanning activity directed against standby members in our gateway clusters, and all the traffic is dropped by existing rules, but we followed the recommendations to enable the penalty box and are still seeing these alerts.&lt;/P&gt;
&lt;P&gt;Is there an optimal set of penalty box paramaters that would catch this traffic and prevent the AIOps alert from triggering?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 May 2026 09:08:14 GMT</pubDate>
    <dc:creator>Scott_Paisley</dc:creator>
    <dc:date>2026-05-12T09:08:14Z</dc:date>
    <item>
      <title>AIOps alerts and penalty box configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AIOps-alerts-and-penalty-box-configuration/m-p/276829#M105341</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;We recently enabled AIOps. We are now getting ferequenst alerts of the following type&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Rulebase drop spike caused by a burst of blocked traffic not a policy or gateway fault.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Rulebase drops rose sharply at 19:33Z and stayed very high for about 20 minutes with no policy change. This points to a burst of un&lt;SPAN data-teams="true"&gt;wanted traffic correctly blocked by existing rules not a gateway failure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Recommendations:&lt;/P&gt;
&lt;UL style="padding-left: 20px;"&gt;
&lt;LI&gt;Implement SecureXL-based DoS defenses including Rate Limiting rules and Penalty Box to block abusive traffic earlier. (sk112241)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We understand this is due to scanning activity directed against standby members in our gateway clusters, and all the traffic is dropped by existing rules, but we followed the recommendations to enable the penalty box and are still seeing these alerts.&lt;/P&gt;
&lt;P&gt;Is there an optimal set of penalty box paramaters that would catch this traffic and prevent the AIOps alert from triggering?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 09:08:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AIOps-alerts-and-penalty-box-configuration/m-p/276829#M105341</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2026-05-12T09:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: AIOps alerts and penalty box configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AIOps-alerts-and-penalty-box-configuration/m-p/276833#M105345</link>
      <description>&lt;P&gt;Please share pbox configuration so I can have a look.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 09:50:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AIOps-alerts-and-penalty-box-configuration/m-p/276833#M105345</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-05-12T09:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: AIOps alerts and penalty box configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AIOps-alerts-and-penalty-box-configuration/m-p/276834#M105346</link>
      <description>&lt;P&gt;Penalty Box:&lt;BR /&gt;Status on&lt;BR /&gt;Internal Interfaces off&lt;BR /&gt;Monitor-Only off&lt;BR /&gt;Log Drops on&lt;BR /&gt;Max Notifications Per-Second 100 logs/second&lt;BR /&gt;Send TCP Reset off&lt;BR /&gt;Timeout for Blocked IPs 180 seconds&lt;BR /&gt;Has Blocked IPs no&lt;BR /&gt;Log when a new IP is blocked on&lt;BR /&gt;Drop rate to trigger on 500 packets/second&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 09:53:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AIOps-alerts-and-penalty-box-configuration/m-p/276834#M105346</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2026-05-12T09:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: AIOps alerts and penalty box configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AIOps-alerts-and-penalty-box-configuration/m-p/276841#M105350</link>
      <description>&lt;P&gt;Please check my white paper on this topic:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Firewall-and-Security-Management/Step-by-step-guide-for-penalty-box-R82-and-R81-20/m-p/276593#M105262" target="_blank"&gt;https://community.checkpoint.com/t5/Firewall-and-Security-Management/Step-by-step-guide-for-penalty-box-R82-and-R81-20/m-p/276593#M105262&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check if you see penatly box becomes active in Smart Console, any drops? Does AIops tell you the ip is doing this? Does this refelect in the penalty box logs?&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 11:25:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AIOps-alerts-and-penalty-box-configuration/m-p/276841#M105350</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-05-12T11:25:16Z</dc:date>
    </item>
  </channel>
</rss>

