- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Drop optimization
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Drop optimization
What is enable drop optimization checkpoint in firewall
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's intended to help with the resource utilization of dropping heavy traffic, please see:
https://support.checkpoint.com/results/sk/sk90861
Also some previous discussion on this topic:
https://community.checkpoint.com/t5/General-Topics/Drop-optimization/td-p/34855
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When it comes to having the firewall efficiently drop floods of traffic, I've always been partial to the SecureXL Penalty Box. Good logging and easy to understand: sk112454: How to configure Rate Limiting rules for DoS Mitigation (R80.20 and higher)
The "Optimized Drops" feature to dynamically form drop templates always seemed a bit clunky to me as it couldn't offload drop templates for complex objects such as Dynamic Objects, and those specific drops still had to happen on a Firewall Worker Instance core. The logging and monitoring was also not very good. However in R81.20 the Optimized Drops feature got some updates to make it more compatible with SecureXL, and also improved the monitoring/logging. Haven't had a chance to try it yet but looks promising: sk175006: Firewall Drop Templates in R81.20 and higher
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's intended to help with the resource utilization of dropping heavy traffic, please see:
https://support.checkpoint.com/results/sk/sk90861
Also some previous discussion on this topic:
https://community.checkpoint.com/t5/General-Topics/Drop-optimization/td-p/34855
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When it comes to having the firewall efficiently drop floods of traffic, I've always been partial to the SecureXL Penalty Box. Good logging and easy to understand: sk112454: How to configure Rate Limiting rules for DoS Mitigation (R80.20 and higher)
The "Optimized Drops" feature to dynamically form drop templates always seemed a bit clunky to me as it couldn't offload drop templates for complex objects such as Dynamic Objects, and those specific drops still had to happen on a Firewall Worker Instance core. The logging and monitoring was also not very good. However in R81.20 the Optimized Drops feature got some updates to make it more compatible with SecureXL, and also improved the monitoring/logging. Haven't had a chance to try it yet but looks promising: sk175006: Firewall Drop Templates in R81.20 and higher
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I been running it in R81.20 labs, its pretty good.
Cheers,
Andy
