<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213483#M40682</link>
    <description>&lt;P&gt;Did you try block using updatable object as a country?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 07 May 2024 12:23:39 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-05-07T12:23:39Z</dc:date>
    <item>
      <title>Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implied ru</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213475#M40676</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implied rules. Below is the rule that was added in the gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;fwaccel dos rate add -action drop -log regular source cc:BR pkt-rate 0 service any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;fwaccel does not block them though the rule blocks Brazil but&amp;nbsp;the idea of the fwaccel rule was to override this implied rule for traffic from Brazil.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can someone please assist ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 11:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213475#M40676</guid>
      <dc:creator>mahesh</dc:creator>
      <dc:date>2024-05-07T11:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213483#M40682</link>
      <description>&lt;P&gt;Did you try block using updatable object as a country?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 12:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213483#M40682</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-07T12:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213488#M40684</link>
      <description>&lt;H2 class="message-subject"&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;fwaccel dos&lt;/SPAN&gt; is meant for D0S attacks, not Geo IP - you can only blacklist IPs and block DoS attacks using a rate limit...&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 12:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213488#M40684</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-05-07T12:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213489#M40685</link>
      <description>&lt;P&gt;Yes, earlier there was a DDOS attack and customer tried blocking the traffic from Brazil using country code "BR" but it did not work so he added manual rules to block the traffic.&lt;/P&gt;&lt;P&gt;Later, we suspected an issue with IpToCountry mapping and so updated the IpToCountry.csv file and then removed all the manual entries and it almost worked fine. But still observing some 443 traffic from Brazil accepted by Implied rules.&lt;/P&gt;&lt;P&gt;I believe fwaccel rule should block all the traffic coming from Brazil but it is still allowed by Implied rules.&lt;/P&gt;&lt;P&gt;Is there any suggestion ?&lt;/P&gt;&lt;P&gt;Appreciate your help !&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 12:58:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213489#M40685</guid>
      <dc:creator>mahesh</dc:creator>
      <dc:date>2024-05-07T12:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213491#M40686</link>
      <description>&lt;P&gt;One thing to check, though dont believe its recommended to modify the implied rules, would be to look at $FWDIR/lim/implied_rules.def file on mgmt server&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 13:06:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213491#M40686</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-07T13:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213492#M40687</link>
      <description>&lt;P&gt;May I ask what to check exactly in the file ?&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 13:09:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213492#M40687</guid>
      <dc:creator>mahesh</dc:creator>
      <dc:date>2024-05-07T13:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213493#M40688</link>
      <description>&lt;P&gt;Not sure at this point. I might be able to make logical guess if you send the implied rule log.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 13:10:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213493#M40688</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-07T13:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213494#M40689</link>
      <description>&lt;P&gt;Below is the log screenshot of Smart console logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 13:28:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213494#M40689</guid>
      <dc:creator>mahesh</dc:creator>
      <dc:date>2024-05-07T13:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213495#M40690</link>
      <description>&lt;P&gt;Can you double click on one of those logs for details?&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 13:30:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213495#M40690</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-07T13:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213496#M40691</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105740" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105740&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 13:31:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213496#M40691</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-05-07T13:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213544#M40698</link>
      <description>&lt;P&gt;A rate limit of zero should prevent any data from passing, but I don't believe it will prevent the connection from being established.&lt;BR /&gt;You may want to confirm this with TAC.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 22:55:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213544#M40698</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-07T22:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213564#M40701</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I am aware of this sk&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;but the idea of the fwaccel rule was to override this implied rule for traffic from Brazil. It should block all the traffic before hitting Implied rules I believe.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 03:28:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213564#M40701</guid>
      <dc:creator>mahesh</dc:creator>
      <dc:date>2024-05-08T03:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213876#M40787</link>
      <description>&lt;P&gt;If i remember correctly, with fwaccel dos rules, log about implied rules are shown like accept but traffic is dropped. I will post reference if i found it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, try traffic from brazil if you can and verify by CLI if traffic is accepted for real or if it is dropped&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 20:13:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213876#M40787</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-05-10T20:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213882#M40790</link>
      <description>&lt;P&gt;Thats true.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 20:53:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213882#M40790</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-10T20:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implie</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213906#M40796</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/31562"&gt;@mahesh&lt;/a&gt;&amp;nbsp;Were you able to sort this out?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2024 12:50:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-from-Brazil-was-blocked-using-fwaccel-dos-rules-but/m-p/213906#M40796</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-11T12:50:30Z</dc:date>
    </item>
  </channel>
</rss>

