<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: implied rules getting hit and dropping traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171467#M31084</link>
    <description>&lt;P&gt;Try turning off&amp;nbsp;&lt;SPAN&gt;Network Quota and verify if this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Feb 2023 06:47:40 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2023-02-15T06:47:40Z</dc:date>
    <item>
      <title>implied rules getting hit and dropping traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171453#M31082</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Started migrating vlans from an internal Cisco ASA to a new VSX cluster. I am now getting some intermittent reports of applications or servers not connecting as expected. When I look through the logs, I see lots of drops related to an implied rule. This is hit by different sources and destinations and different ports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;After following&amp;nbsp;&lt;SPAN&gt;sk110218, I am able to see the implied rule name, which is "Implied Rule - enforce_net_quota". The name of this rul seems to indicate I'm hitting some sort of limit but not sure what. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anyone tell me what enforce_net_quota refers to please?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Many Thanks&lt;BR /&gt;Roy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 16:54:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171453#M31082</guid>
      <dc:creator>Roy_Smith</dc:creator>
      <dc:date>2023-02-14T16:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: implied rules getting hit and dropping traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171467#M31084</link>
      <description>&lt;P&gt;Try turning off&amp;nbsp;&lt;SPAN&gt;Network Quota and verify if this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 06:47:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171467#M31084</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2023-02-15T06:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: implied rules getting hit and dropping traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171482#M31087</link>
      <description>&lt;P&gt;Can you send screencap of it if possible? I checked sk you mentioned, but does not sadly seem too useful here. I also saw what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;suggested, but cant find that protection even in my R81.20 lab with updated IPS.&lt;/P&gt;
&lt;P&gt;Searching CP support site, cant find much on it, so might be worth if you do zdebug to verify if you get exact same messages. We might be able to figure out from those drops if there is indeed actual IPS protection causing an issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 18:45:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171482#M31087</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-14T18:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: implied rules getting hit and dropping traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171508#M31097</link>
      <description>&lt;P&gt;This is definitely the Network Quota protection, which is inactive by default.&lt;BR /&gt;You can do one of two things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Disable it by going to&amp;nbsp;&lt;SPAN&gt;Security Policies &amp;gt; Inspection Settings and setting it to Inactive for the relevant profile&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Create an exception for the relevant traffic in the protection&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Changing this setting requires pushing the Access Policy (not Threat Prevention) since this is a Core Protection handled by the firewall (not IPS).&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 22:01:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171508#M31097</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-14T22:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: implied rules getting hit and dropping traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171533#M31099</link>
      <description>&lt;P&gt;Ah, inspection setting, thats why I could not find it...duh, silly me. Anyway, let us know&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18838"&gt;@Roy_Smith&lt;/a&gt;&amp;nbsp;if what phoneboy suggested works.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 01:37:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171533#M31099</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-15T01:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: implied rules getting hit and dropping traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171642#M31126</link>
      <description>&lt;P&gt;Guys&lt;/P&gt;&lt;P&gt;It was the Network Quota in Inspections Settings that was being referred to. I set it back to inactive and that solved the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 04:51:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/171642#M31126</guid>
      <dc:creator>Roy_Smith</dc:creator>
      <dc:date>2023-02-16T04:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: implied rules getting hit and dropping traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/258440#M50689</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Any reason why the default for this setting is disabled? I've found it as enabled in my environment and was thinking it could be useful to fend off DoS attacks?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 10:23:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/258440#M50689</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2025-09-29T10:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: implied rules getting hit and dropping traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/258508#M50698</link>
      <description>&lt;P&gt;Network Quota has a performance impact of Critical, which is why it is disabled by default.&lt;BR /&gt;If you're looking to mitigate DoS attacks, you're far better off using fwaccel dos, which is SecureXL friendly.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk112454" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112454&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 00:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/258508#M50698</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-30T00:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: implied rules getting hit and dropping traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/259126#M50818</link>
      <description>&lt;P&gt;Will look into this. Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 15:06:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/implied-rules-getting-hit-and-dropping-traffic/m-p/259126#M50818</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2025-10-06T15:06:23Z</dc:date>
    </item>
  </channel>
</rss>

