<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Checkpoint 5200 PB-20 IPS can inspect Mysql packets? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162409#M28873</link>
    <description>&lt;P&gt;Review the IPS Protections for yourself to see what will be blocked.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="85CFBAE2-AE6C-46E0-BF5B-656F9C02A4A6.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18456iF719028E9E9D0A83/image-size/large?v=v2&amp;amp;px=999" role="button" title="85CFBAE2-AE6C-46E0-BF5B-656F9C02A4A6.jpeg" alt="85CFBAE2-AE6C-46E0-BF5B-656F9C02A4A6.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;What is your precise definition of “massive TCP connections”?&lt;BR /&gt;If you’re concerned about that happening, you can use the ratelimiting functions.&amp;nbsp;&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-DDoS-fw-sam-vs-fwaccel-dos/td-p/41525" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-DDoS-fw-sam-vs-fwaccel-dos/td-p/41525&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Nov 2022 23:28:10 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-11-17T23:28:10Z</dc:date>
    <item>
      <title>Can Checkpoint 5200 PB-20 IPS can inspect Mysql packets?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162266#M28843</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Can Checkpoint&amp;nbsp;5200 PB-20 IPS assess the content from incoming packets for Mysql database server (port 3306)? If the packet is according to a real Mysql packet then this can be forwarded to the database server, otherwise it will be dropped. The idea is to avoid DDOS attacks by sending massive TCP connections to Mysql server by Telnet or another application.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 19:27:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162266#M28843</guid>
      <dc:creator>userLearnCP</dc:creator>
      <dc:date>2022-11-16T19:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can Checkpoint 5200 PB-20 IPS can inspect Mysql packets?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162290#M28844</link>
      <description>&lt;P&gt;Yes, it can.&lt;BR /&gt;However, I’m curious why the concern about DDoS since a MySQL server should only be accessed from specific hosts, not generally accessible from the Internet.&lt;BR /&gt;While we can do some rate limiting and such if required, if you’re really concerned about DDoS,&amp;nbsp;Check Point sells specific solutions for this.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 21:24:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162290#M28844</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-16T21:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can Checkpoint 5200 PB-20 IPS can inspect Mysql packets?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162294#M28845</link>
      <description>&lt;P&gt;My suspect it's not about someone from outside but It's someone from inside who can execute it from these specific hosts even.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the following questions:&lt;/P&gt;&lt;P&gt;1) By customizing Threat Prevention with IPS would help in case of malformed mysql packets?&lt;/P&gt;&lt;P&gt;2) There is an option of 'IPS Protections' from SmartConsole. Can one of these protections match about the&amp;nbsp;case I explained?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 22:31:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162294#M28845</guid>
      <dc:creator>userLearnCP</dc:creator>
      <dc:date>2022-11-16T22:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can Checkpoint 5200 PB-20 IPS can inspect Mysql packets?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162409#M28873</link>
      <description>&lt;P&gt;Review the IPS Protections for yourself to see what will be blocked.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="85CFBAE2-AE6C-46E0-BF5B-656F9C02A4A6.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18456iF719028E9E9D0A83/image-size/large?v=v2&amp;amp;px=999" role="button" title="85CFBAE2-AE6C-46E0-BF5B-656F9C02A4A6.jpeg" alt="85CFBAE2-AE6C-46E0-BF5B-656F9C02A4A6.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;What is your precise definition of “massive TCP connections”?&lt;BR /&gt;If you’re concerned about that happening, you can use the ratelimiting functions.&amp;nbsp;&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-DDoS-fw-sam-vs-fwaccel-dos/td-p/41525" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-DDoS-fw-sam-vs-fwaccel-dos/td-p/41525&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 23:28:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162409#M28873</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-17T23:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can Checkpoint 5200 PB-20 IPS can inspect Mysql packets?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162491#M28904</link>
      <description>&lt;P&gt;Thanks for the picture and the link.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What is your precise definition of “massive TCP connections”?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- I mean multiple TCP connections. I tried to mention it as a synonym. These connections are associated with packets.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 19:57:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Checkpoint-5200-PB-20-IPS-can-inspect-Mysql-packets/m-p/162491#M28904</guid>
      <dc:creator>userLearnCP</dc:creator>
      <dc:date>2022-11-18T19:57:43Z</dc:date>
    </item>
  </channel>
</rss>

