<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Penalty Box ist not reboot safe in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Penalty-Box-ist-not-reboot-safe/m-p/83374#M11226</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I want to enable the penalty Box. i executed the follwing commands:&lt;/P&gt;&lt;P&gt;fwaccel dos config set --enable-monitor&lt;/P&gt;&lt;P&gt;fwaccel dos config set --enable-pbox&lt;/P&gt;&lt;P&gt;after this the pbox is enabled and does work:&lt;/P&gt;&lt;P&gt;fwaccel dos config get&lt;BR /&gt;rate limit: disabled (without policy)&lt;BR /&gt;pbox: enabled&lt;BR /&gt;blacklists: disabled&lt;BR /&gt;drop frags: disabled&lt;BR /&gt;drop opts: disabled&lt;BR /&gt;internal: disabled&lt;BR /&gt;monitor: enabled&lt;BR /&gt;log drops: enabled&lt;BR /&gt;log pbox: enabled&lt;BR /&gt;notif rate: 100 notifications/second&lt;BR /&gt;pbox rate: 500 packets/second&lt;BR /&gt;pbox tmo: 180 seconds&lt;/P&gt;&lt;P&gt;but after a reboot of the firewall the pbox is disabled again. what have i to do to make this reboot safe? i cannot find id in the documentation.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Apr 2020 17:56:19 GMT</pubDate>
    <dc:creator>David_T</dc:creator>
    <dc:date>2020-04-27T17:56:19Z</dc:date>
    <item>
      <title>Penalty Box ist not reboot safe</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Penalty-Box-ist-not-reboot-safe/m-p/83374#M11226</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I want to enable the penalty Box. i executed the follwing commands:&lt;/P&gt;&lt;P&gt;fwaccel dos config set --enable-monitor&lt;/P&gt;&lt;P&gt;fwaccel dos config set --enable-pbox&lt;/P&gt;&lt;P&gt;after this the pbox is enabled and does work:&lt;/P&gt;&lt;P&gt;fwaccel dos config get&lt;BR /&gt;rate limit: disabled (without policy)&lt;BR /&gt;pbox: enabled&lt;BR /&gt;blacklists: disabled&lt;BR /&gt;drop frags: disabled&lt;BR /&gt;drop opts: disabled&lt;BR /&gt;internal: disabled&lt;BR /&gt;monitor: enabled&lt;BR /&gt;log drops: enabled&lt;BR /&gt;log pbox: enabled&lt;BR /&gt;notif rate: 100 notifications/second&lt;BR /&gt;pbox rate: 500 packets/second&lt;BR /&gt;pbox tmo: 180 seconds&lt;/P&gt;&lt;P&gt;but after a reboot of the firewall the pbox is disabled again. what have i to do to make this reboot safe? i cannot find id in the documentation.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 17:56:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Penalty-Box-ist-not-reboot-safe/m-p/83374#M11226</guid>
      <dc:creator>David_T</dc:creator>
      <dc:date>2020-04-27T17:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Penalty Box ist not reboot safe</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Penalty-Box-ist-not-reboot-safe/m-p/83397#M11227</link>
      <description>&lt;P&gt;Quoted from sk74520:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Important note:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Note that in order for this configuration to be persistent and survive a reboot, add the relevant '&lt;CODE&gt;sim erdos&lt;/CODE&gt;' commands at the bottom of the &lt;STRONG&gt;&lt;CODE&gt;/etc/rc.d/rc.local&lt;/CODE&gt;&lt;/STRONG&gt; shell script.&lt;/P&gt;
&lt;P&gt;The above applies to R80.30 and older, for R80.40 this is quoted from sk112454:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Except for rate limiting policy rules, configuration changes made using the "fwaccel dos" command are *not* automatically saved. To make the changes permanent, IPv4 commands can be added to the following shell script on the security gateway:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px" style="padding-left: 30px;"&gt;&lt;STRONG&gt;$FWDIR/conf/fwaccel_dos_rate_on_install&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 20:54:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Penalty-Box-ist-not-reboot-safe/m-p/83397#M11227</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-27T20:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Penalty Box ist not reboot safe</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Penalty-Box-ist-not-reboot-safe/m-p/83430#M11228</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thank for your answer. i have 80.30. i dont have the sim erdos commands. does this also work with the new commands?&lt;/P&gt;&lt;P&gt;should i add&amp;nbsp;&lt;/P&gt;&lt;P&gt;fwaccel dos config set --enable-monitor&lt;/P&gt;&lt;P&gt;fwaccel dos config set --enable-pbox&lt;/P&gt;&lt;P&gt;to&amp;nbsp;&lt;STRONG&gt;/etc/rc.d/rc.local ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 06:12:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Penalty-Box-ist-not-reboot-safe/m-p/83430#M11228</guid>
      <dc:creator>David_T</dc:creator>
      <dc:date>2020-04-28T06:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Penalty Box ist not reboot safe</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Penalty-Box-ist-not-reboot-safe/m-p/83433#M11229</link>
      <description>Applies for that as well.</description>
      <pubDate>Tue, 28 Apr 2020 06:16:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Penalty-Box-ist-not-reboot-safe/m-p/83433#M11229</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-28T06:16:44Z</dc:date>
    </item>
  </channel>
</rss>

