<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: what is the limit  for the concurrent connections in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195730#M36498</link>
    <description>&lt;P&gt;Here's an example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aa.png" style="width: 834px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22886i659EBD2F54F4CD00/image-size/large?v=v2&amp;amp;px=999" role="button" title="aa.png" alt="aa.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Aggressive-Aging/td-p/49209" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Aggressive-Aging/td-p/49209&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Oct 2023 06:39:14 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-10-20T06:39:14Z</dc:date>
    <item>
      <title>what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194785#M36263</link>
      <description>&lt;P&gt;what is the limit or default value of concurrent connections ?&lt;/P&gt;&lt;P&gt;will the command fw ctl pstat will also include any expired sessions in the value ?&lt;/P&gt;&lt;P&gt;how to check any&amp;nbsp; expired connections where present in the concurrent connections when we run the fw ctl pstat ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 10:54:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194785#M36263</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-10-11T10:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194840#M36265</link>
      <description>&lt;P&gt;Unless you've explicitly set a limit, the limit is available memory, and depends on the features enabled.&lt;BR /&gt;The datasheet for the relevant appliance will tell you what is supported in this regard.&lt;/P&gt;
&lt;P&gt;The connections table only includes active connections.&lt;BR /&gt;Once a connection terminates, expires, or is removed due to "aggressive aging" (an IPS protection), they are removed from the connections table.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 15:13:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194840#M36265</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-11T15:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194857#M36267</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;explained it perfectly, thats your answer.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 16:39:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194857#M36267</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T16:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194905#M36278</link>
      <description>&lt;P&gt;for 15600 appliance in datasheet what the limit ? and there are 4 VS&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 04:35:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194905#M36278</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-10-12T04:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194912#M36280</link>
      <description>&lt;P&gt;Datasheet has:&lt;/P&gt;
&lt;DIV class="page" title="Page 4"&gt;
&lt;DIV class="section"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P&gt;&lt;SPAN&gt;5 to 10 million concurrent connections, 64 byte response &lt;/SPAN&gt;&lt;SPAN&gt;(performance measured with default/maximum memory) &lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 12 Oct 2023 07:20:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194912#M36280</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-12T07:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194927#M36282</link>
      <description>&lt;P&gt;In VSX the limit is manually set / configured per VS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should review it on a needs basis considering expected traffic &amp;amp; available memory capacity.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 12:06:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194927#M36282</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-12T12:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194954#M36288</link>
      <description>&lt;P&gt;Depends on how much RAM you have. Check the output of 'free -h'. Subtract 3 GB for the OS. For just firewalling, 500k per gigabyte remaining is reasonable. For firewalling plus IPS plus threat emulation plus whatever else, expect more like 200k connections per gigabyte.&lt;/P&gt;
&lt;P&gt;With VSX, the above gives you the total capacity of the box, which you then manually split between VSs. Even with a base 15600 with four VSs, you should be able to get over half a million connections per VS without going to extreme lengths.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 14:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194954#M36288</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-10-12T14:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194955#M36289</link>
      <description>&lt;P&gt;Thats interesting. Just curious, does such calculation apply to ANY cp setup, regardless if its physical appliance or VM/open server?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 14:39:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194955#M36289</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-12T14:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194957#M36290</link>
      <description>&lt;P&gt;Absolutely. Check Point's branded boxes are just open servers with weird PCIe slots. Take a look at the datasheets for the &lt;A href="https://www.checkpoint.com/downloads/products/15600-security-gateway-datasheet.pdf" target="_self"&gt;15600&lt;/A&gt;, &lt;A href="https://www.checkpoint.com/downloads/products/16200-security-gateway-datasheet.pdf" target="_self"&gt;16200&lt;/A&gt;, &lt;A href="https://www.checkpoint.com/downloads/products/qls250-lightspeed-firewall-datasheet.pdf" target="_self"&gt;QLS250&lt;/A&gt;, etc. Very roughly, they say 16 GB supports ~6M connections, 32 GB supports 8-12M, 64 GB supports 16-25M, and 128 GB supports ~32M. Newer datasheets revise the connections per gigabyte down as new features consume some RAM.&lt;/P&gt;
&lt;P&gt;The important thing to keep in mind is that the OS consumes some amount (generally fairly constant, and generally goes up a little with each major version), and the features you enable consume some amount per instance of the feature (i.e, per VS with it enabled).&lt;/P&gt;
&lt;P&gt;RAM is cheap. If you're building a firewall for a given connection capacity, go with the 200k per gigabyte (or even 150k per gigabyte), give yourself an extra 25%, and round up to the next stick you need for optimal bank interleaving.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 15:31:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194957#M36290</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-10-12T15:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194958#M36291</link>
      <description>&lt;P&gt;That makes sense. I will say though that like most fw vendors, those data sheets represent PERFECT scenario, which literally never happens, and take into an account single rule any any allow, thats it. They dont really represent any customer's actual live environment.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 15:37:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194958#M36291</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-12T15:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194982#M36292</link>
      <description>&lt;P&gt;Connection capacity is much less sensitive to the environment than throughput is. The only real way to reduce it is enabling the deep inspection features which consume more baseline RAM, leaving less space for connections. Without those, you can actually get much higher connection counts than the datasheets suggest for a given amount of RAM.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 18:33:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/194982#M36292</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-10-12T18:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195008#M36296</link>
      <description>&lt;P&gt;is there any way that we can set an alerts messages in smart console or any where, when the concurrent connection reach to 80%&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 05:30:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195008#M36296</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-10-13T05:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195085#M36304</link>
      <description>&lt;P&gt;The only way to get those alerts in SmartConsole is to enable Aggressive Aging.&lt;BR /&gt;However, it will be based on overall memory usage, not percentage of the connections table being full:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk122154" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk122154&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Otherwise, it will need to be monitored with SNMP, Skyline, or something else.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 15:07:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195085#M36304</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-13T15:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195228#M36328</link>
      <description>&lt;P&gt;can explain how we get an get an alert if we enable AA and how does it will works ?&lt;/P&gt;&lt;P&gt;and also any command to delete the TCP connections&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 04:46:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195228#M36328</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-10-16T04:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195286#M36333</link>
      <description>&lt;P&gt;Aggressive Aging will generate specific logs when it is activated.&lt;BR /&gt;If you have SmartEvent, you should be able to run a report/trigger an alert on one of these logs.&lt;/P&gt;
&lt;P&gt;While it is possible to remove entries from the firewall tables (including connections) using fw tab -x (with correct arguments), this is not recommended.&lt;BR /&gt;Refer to the docs:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-tab.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-tab.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 14:55:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195286#M36333</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-16T14:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195720#M36491</link>
      <description>&lt;P&gt;when AA is enabled what logs will generate ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;when we have smart event on what logs we can run report/tigger report ?&lt;/P&gt;&lt;P&gt;if possible can explain more ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 04:57:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195720#M36491</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2023-10-20T04:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195730#M36498</link>
      <description>&lt;P&gt;Here's an example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aa.png" style="width: 834px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22886i659EBD2F54F4CD00/image-size/large?v=v2&amp;amp;px=999" role="button" title="aa.png" alt="aa.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Aggressive-Aging/td-p/49209" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Aggressive-Aging/td-p/49209&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 06:39:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/195730#M36498</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-20T06:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/205012#M38654</link>
      <description>&lt;P&gt;can we set the concurrent connection limit for specific rule which have small gruop of users ?&lt;/P&gt;&lt;P&gt;if yes how can get this configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 07:14:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/205012#M38654</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2024-02-05T07:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/205035#M38656</link>
      <description>&lt;P&gt;Never heard of that, but would be really useful if it can be done. Closest I can think of something like that would be QoS.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 10:31:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/205035#M38656</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-05T10:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: what is the limit  for the concurrent connections</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/205057#M38660</link>
      <description>&lt;P&gt;Sort of, check out the&amp;nbsp;&lt;EM&gt;concurrent-conns &lt;/EM&gt;and&amp;nbsp;&lt;EM&gt;concurrent-conns-ratio&lt;/EM&gt; options to &lt;STRONG&gt;fwaccel dos&lt;/STRONG&gt;:&amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk112454" target="_blank" rel="noopener"&gt;sk112454: How to configure Rate Limiting rules for&amp;nbsp;DoS&amp;nbsp;Mitigation (R80.20 and higher)&amp;nbsp;&lt;/A&gt;&amp;nbsp; &amp;nbsp;You can also limit new connection rates as well.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However this mechanism is implemented in SecureXL and thus can only match IP addresses/ranges/networks and/or port numbers for enforcement; it cannot leverage user identity/group information to my knowledge.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 14:35:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/what-is-the-limit-for-the-concurrent-connections/m-p/205057#M38660</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-02-05T14:35:52Z</dc:date>
    </item>
  </channel>
</rss>

