- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
What is enable drop optimization checkpoint in firewall
It's intended to help with the resource utilization of dropping heavy traffic, please see:
https://support.checkpoint.com/results/sk/sk90861
Also some previous discussion on this topic:
https://community.checkpoint.com/t5/General-Topics/Drop-optimization/td-p/34855
When it comes to having the firewall efficiently drop floods of traffic, I've always been partial to the SecureXL Penalty Box. Good logging and easy to understand: sk112454: How to configure Rate Limiting rules for DoS Mitigation (R80.20 and higher)
The "Optimized Drops" feature to dynamically form drop templates always seemed a bit clunky to me as it couldn't offload drop templates for complex objects such as Dynamic Objects, and those specific drops still had to happen on a Firewall Worker Instance core. The logging and monitoring was also not very good. However in R81.20 the Optimized Drops feature got some updates to make it more compatible with SecureXL, and also improved the monitoring/logging. Haven't had a chance to try it yet but looks promising: sk175006: Firewall Drop Templates in R81.20 and higher
It's intended to help with the resource utilization of dropping heavy traffic, please see:
https://support.checkpoint.com/results/sk/sk90861
Also some previous discussion on this topic:
https://community.checkpoint.com/t5/General-Topics/Drop-optimization/td-p/34855
When it comes to having the firewall efficiently drop floods of traffic, I've always been partial to the SecureXL Penalty Box. Good logging and easy to understand: sk112454: How to configure Rate Limiting rules for DoS Mitigation (R80.20 and higher)
The "Optimized Drops" feature to dynamically form drop templates always seemed a bit clunky to me as it couldn't offload drop templates for complex objects such as Dynamic Objects, and those specific drops still had to happen on a Firewall Worker Instance core. The logging and monitoring was also not very good. However in R81.20 the Optimized Drops feature got some updates to make it more compatible with SecureXL, and also improved the monitoring/logging. Haven't had a chance to try it yet but looks promising: sk175006: Firewall Drop Templates in R81.20 and higher
I been running it in R81.20 labs, its pretty good.
Cheers,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY