- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Traffic from Brazil was blocked using fwaccel dos rules but seeing 443 traffic allowed by Implied rules. Below is the rule that was added in the gateway.
fwaccel dos rate add -action drop -log regular source cc:BR pkt-rate 0 service any
fwaccel does not block them though the rule blocks Brazil but the idea of the fwaccel rule was to override this implied rule for traffic from Brazil.
Can someone please assist ?
Did you try block using updatable object as a country?
Andy
Yes, earlier there was a DDOS attack and customer tried blocking the traffic from Brazil using country code "BR" but it did not work so he added manual rules to block the traffic.
Later, we suspected an issue with IpToCountry mapping and so updated the IpToCountry.csv file and then removed all the manual entries and it almost worked fine. But still observing some 443 traffic from Brazil accepted by Implied rules.
I believe fwaccel rule should block all the traffic coming from Brazil but it is still allowed by Implied rules.
Is there any suggestion ?
Appreciate your help !
One thing to check, though dont believe its recommended to modify the implied rules, would be to look at $FWDIR/lim/implied_rules.def file on mgmt server
Andy
May I ask what to check exactly in the file ?
Not sure at this point. I might be able to make logical guess if you send the implied rule log.
Andy
Can you double click on one of those logs for details?
https://support.checkpoint.com/results/sk/sk105740
I am aware of this sk but the idea of the fwaccel rule was to override this implied rule for traffic from Brazil. It should block all the traffic before hitting Implied rules I believe.
A rate limit of zero should prevent any data from passing, but I don't believe it will prevent the connection from being established.
You may want to confirm this with TAC.
If i remember correctly, with fwaccel dos rules, log about implied rules are shown like accept but traffic is dropped. I will post reference if i found it
Anyway, try traffic from brazil if you can and verify by CLI if traffic is accepted for real or if it is dropped
Thats true.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY