Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
flachance
MVP Silver
MVP Silver
Jump to solution

out of the box DoS protection

I can't seem to find clear information for that anywhere. When deploying a gateway is there any DoS protection included/activated by default?

Or do you have to configure Rate limiting rules (sk112454)?

We're on R81.20

0 Kudos
1 Solution

Accepted Solutions
Tal_Paz-Fridman
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Please refer to:

Important changes in the IPS "SYN Attack" (SYN Defender) protection

https://support.checkpoint.com/results/sk/sk120476 

 

Also to:
sk112454 - How to configure Rate Limiting rules for DoS Mitigation in R80.20 - R81.20

https://support.checkpoint.com/results/sk/sk112454 

View solution in original post

6 Replies
Tal_Paz-Fridman
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Please refer to:

Important changes in the IPS "SYN Attack" (SYN Defender) protection

https://support.checkpoint.com/results/sk/sk120476 

 

Also to:
sk112454 - How to configure Rate Limiting rules for DoS Mitigation in R80.20 - R81.20

https://support.checkpoint.com/results/sk/sk112454 

flachance
MVP Silver
MVP Silver

thanks. So nothing out of the box. Both have to be configured / enabled.

SYN Defender is fairly straight forward.

Rate limiting rules not so much. From the examples it looks like you have to specify a source IP. Maybe I’m not reading these rights but then you’d have to know about a problematic IP in advanced?

Also what would be a good general number for the maximum number of concurrent active connections to start with?

0 Kudos
the_rock
MVP Diamond
MVP Diamond

I would enable below, if I were you. That way, fw would adjust memory/cpu usage based on amount of connections.

Screenshot_1.png

Best,
Andy
"Have a great day and if its not, change it"
flachance
MVP Silver
MVP Silver


Thanks it's already configured this way. So i guess there is something out of the box 😁

the_rock
MVP Diamond
MVP Diamond

If you say so ; - )

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
the_rock
MVP Diamond
MVP Diamond

I would also refer to links Tal provided.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events