Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gacki
Participant
Jump to solution

Drop optimization

What is enable drop optimization checkpoint in firewall

0 Kudos
2 Solutions

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

It's intended to help with the resource utilization of dropping heavy traffic, please see:  

https://support.checkpoint.com/results/sk/sk90861

Also some previous discussion on this topic:

https://community.checkpoint.com/t5/General-Topics/Drop-optimization/td-p/34855

 

CCSM R77/R80/ELITE

View solution in original post

0 Kudos
Timothy_Hall
Legend Legend
Legend

When it comes to having the firewall efficiently drop floods of traffic, I've always been partial to the SecureXL Penalty Box.  Good logging and easy to understand: sk112454: How to configure Rate Limiting rules for DoS Mitigation (R80.20 and higher)

The "Optimized Drops" feature to dynamically form drop templates always seemed a bit clunky to me as it couldn't offload drop templates for complex objects such as Dynamic Objects, and those specific drops still had to happen on a Firewall Worker Instance core.  The logging and monitoring was also not very good. However in R81.20 the Optimized Drops feature got some updates to make it more compatible with SecureXL, and also improved the monitoring/logging.  Haven't had a chance to try it yet but looks promising:  sk175006: Firewall Drop Templates in R81.20 and higher

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

(1)
3 Replies
Chris_Atkinson
Employee Employee
Employee

It's intended to help with the resource utilization of dropping heavy traffic, please see:  

https://support.checkpoint.com/results/sk/sk90861

Also some previous discussion on this topic:

https://community.checkpoint.com/t5/General-Topics/Drop-optimization/td-p/34855

 

CCSM R77/R80/ELITE
0 Kudos
Timothy_Hall
Legend Legend
Legend

When it comes to having the firewall efficiently drop floods of traffic, I've always been partial to the SecureXL Penalty Box.  Good logging and easy to understand: sk112454: How to configure Rate Limiting rules for DoS Mitigation (R80.20 and higher)

The "Optimized Drops" feature to dynamically form drop templates always seemed a bit clunky to me as it couldn't offload drop templates for complex objects such as Dynamic Objects, and those specific drops still had to happen on a Firewall Worker Instance core.  The logging and monitoring was also not very good. However in R81.20 the Optimized Drops feature got some updates to make it more compatible with SecureXL, and also improved the monitoring/logging.  Haven't had a chance to try it yet but looks promising:  sk175006: Firewall Drop Templates in R81.20 and higher

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
(1)
the_rock
Legend
Legend

I been running it in R81.20 labs, its pretty good.

Cheers,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events