- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
One of our Major Account customer (Stock Exchange) would like to configure the connection limit for specific source, Destination and Service. (the same way where Cisco ASA can set the connection limit for particular access-list)
Can we achieve this if yes, who can we do that?
Use Check Point Qos and define your required limit.
There is so many limitation if we use the QOS blade. Do was have any other way where we can set this or use any way to configure embryonic connection limit.
Customer was using Cisco ASA and refreshed it with 5800-NGTP and now they want to the same function as per below below cisco link
Without QOS who can we handle this. Also who we handle the embryonic connections and can we set the limit and timeout for those.
Session Timeouts can be configured within service objects:
Thanks Danny, but this will not helpful in this scenario,
...and Danny Jung's suggestion for regular session timeouts.
Maybe a rate limiting rule with fw samp?
sk112454
LIMIT1-NAME LIMIT1-VALUE LIMIT2-NAME LIMIT2-VALUE ... | Specifies quota limits and their values:
|
[Expert@HostName:0]# fw [-d] samp add [-S <SAM_Server>] [-t <Timeout>] {-a <d|r|n|b|q|i>} [-l <r|a>] [-n <name>] [-c <comment>] [-o <originator>] {ip <IP filter arguments>|quota <Quota filter arguments>}
untested
fw samp add -n 10_conns ip -s 192.168.0.0 -m 255.255.0.0 -d 10.1.1.1 -m 255.255.255.255 quota concurrent-conns 10
Well, SAMP will create whole new set of rules that have to be correlated to the security policy.
It would be nice if in addition to the bandwidth limits already available for any rule, the limits for concurrent connections are introduced.
Is there any roadmap to provide this configuration via smart Console in near future?
I don't think so. The nearest roadmap is the one for R80.20 which doesn't list SAM policies.
The options for doing this today are pretty well detailed in this thread.
If you're looking for a different way to do it, then it would have to be handled as an RFE through Solution Center.
Hello Mahipal Singh,
You can use samp rule as below for this your requirement.
example;
fw samp add -a d -l r quota service 17/123 source any destination any concurrent-conns 100000 flush true
Example of Rate Limiting HTTP Connections:
This rule limits connections on TCP port 80 to the server at 192.168.3.4. The limit is 20 new connections per
second, per client, and the rule times out after 1 hour (3600 seconds):
fw samp add -a d -l r -t 3600 quota service 6/80 destination cidr:192.168.3.4/32 new-conn-rate 20 track source flush true
If a majority of the DoS traffic is coming from a specific region, add the source option to the rule. For
example, this rule applies only to hosts from Botland, with country code QQ (an imaginary country):
fw samp add -a d -l r -t 3600 quota service 6/80 source cc:QQ destination cidr:192.168.3.4/32 new-conn-rate 20 track source flush true
Example of a rule with ASN:
This rule drops all packets (-a d) with the source IP address in the IPv4 address block
(cidr:192.0.2.0/24), from the autonomous system number 64500 (asn:AS64500😞
fw samp -a d quota source asn:AS64500,cidr:192.0.2.0/24 service any pkt-rate 0
flush true
Good Luck,
Ali
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
12 | |
11 | |
11 | |
7 | |
7 | |
6 | |
5 | |
5 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY