<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: traffic shaping - by ip subnet in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173600#M31572</link>
    <description>&lt;P&gt;Only the QoS blade allows you to declare the upstream speed to a lower value for a particular interface (in your case 1Gbps-&amp;gt;100Mbps) and then shape the outbound traffic to fit into the lower bandwidth.&amp;nbsp; &lt;STRONG&gt;fwaccel dos&lt;/STRONG&gt; will just drop everything that exceeds a bandwidth limit, and APCL/URLF limits are only per-rule and not per-interface.&amp;nbsp; Looks like the QoS blade is the solution here.&lt;/P&gt;</description>
    <pubDate>Sun, 05 Mar 2023 14:31:57 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2023-03-05T14:31:57Z</dc:date>
    <item>
      <title>traffic shaping - by ip subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173550#M31563</link>
      <description>&lt;P&gt;I am searching for a way to implement some traffic shaping on a per subnet basis.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a hub and spoke type topology where ALL traffic flows thru a central location (Datacenter) w/ a pair of 6200's in Cluster XL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and another question does the checkpoint implement flow control by default???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 20:13:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173550#M31563</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2023-03-03T20:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: traffic shaping - by ip subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173562#M31564</link>
      <description>&lt;P&gt;What's possible from a QoS perspective is covered in the QoS admin guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_QoS_AdminGuide/Default.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_QoS_AdminGuide/Default.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Application Control additionally has a "limit" feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 23:17:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173562#M31564</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-03T23:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: traffic shaping - by ip subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173581#M31568</link>
      <description>&lt;P&gt;There are three ways to do limits, listed below in increasing order of capability &amp;amp; complexity:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If you just want to do simple bandwidth limits, as Chris said you can enforce a per-rule limit from the Action field of a policy layer that has APCL/URLF enabled.&lt;/LI&gt;
&lt;LI&gt;You can also have SecureXL impose various limits including bandwidth, connection rate, total concurrent connections, packet rate, byte rate, etc.&amp;nbsp; See section 5 covering &lt;STRONG&gt;fwaccel dos&lt;/STRONG&gt; here:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112454&amp;amp;partition=Advanced&amp;amp;product=SecureXL," target="_blank" rel="noopener"&gt;sk112454: How to configure Rate Limiting rules for DoS Mitigation (R80.20 and higher)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Finally there is the QoS blade which can enforce weighted fair queuing, per-connection &amp;amp; per-rule limits, per-rule &amp;amp; per-connection bandwidth guarantees, ToS differentiated services, low latency queuing and more.&amp;nbsp; Note that use of QoS now no longer dooms shaped traffic to the F2F/slowpath starting in R80.20, and therefore is now a quite viable option.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;When you say "flow control" I assume you are talking about Ethernet flow control (pause frames)?&amp;nbsp; By default most firewall NICs/drivers will have this enabled by default, but most switches including Cisco will have it off by default so there will be no effect.&amp;nbsp; Generally if flow control is being requested by a firewall NIC it indicates that NIC hardware buffer overruns (RX-OVR) have occurred or are imminent, and you should either use a faster interface if available, or implement a bond.&amp;nbsp; In some rare cases under heavy load Ethernet flow control and TCP's congestion control algorithm can "butt heads" and actually hurt performance due to a phenomenon known as "head of line blocking".&amp;nbsp; This was discussed in my Max Power book and as such Ethernet flow control is generally not desirable in most situations.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Mar 2023 14:49:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173581#M31568</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-03-04T14:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: traffic shaping - by ip subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173582#M31569</link>
      <description>&lt;P&gt;thanks for the reply, ya what is happening on our line is the following.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;our main line is 1 Gbps and our destination switch handoff is only 100 Mbps so we are seeing a bunch of dropped packets. (our switch does not have enough buffer)&lt;/P&gt;
&lt;P&gt;I belive we want to force the connection speed to 100 Mbps for this one specific connection thru our checkpoint .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Mar 2023 15:48:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173582#M31569</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2023-03-04T15:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: traffic shaping - by ip subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173600#M31572</link>
      <description>&lt;P&gt;Only the QoS blade allows you to declare the upstream speed to a lower value for a particular interface (in your case 1Gbps-&amp;gt;100Mbps) and then shape the outbound traffic to fit into the lower bandwidth.&amp;nbsp; &lt;STRONG&gt;fwaccel dos&lt;/STRONG&gt; will just drop everything that exceeds a bandwidth limit, and APCL/URLF limits are only per-rule and not per-interface.&amp;nbsp; Looks like the QoS blade is the solution here.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Mar 2023 14:31:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/173600#M31572</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-03-05T14:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: traffic shaping - by ip subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/174211#M31706</link>
      <description>&lt;P&gt;Hey TImothy, fwaccel dos settings will be lost during an upgrade?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 11:29:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/174211#M31706</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-03-09T11:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: traffic shaping - by ip subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/174255#M31715</link>
      <description>&lt;P&gt;They should not be lost upon upgrade, but for anything that is configured only from the CLI like this it is very important to document these changes, and reverify them after an upgrade/hardware swap.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 14:58:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/traffic-shaping-by-ip-subnet/m-p/174255#M31715</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-03-09T14:58:53Z</dc:date>
    </item>
  </channel>
</rss>

