Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 

Time Limits Not Killing Active Connections

Hello,

I'm running R80.30 and I have a rule setup to drop any traffic from a specific IP range to the Internet, every day from Midnight until 0600.

The rule is working and does not allow any new connections during that time, but it doesn't drop active connections. In SmartView Tracker, I can see a few connections still open from that IP range, and users are still online.  I have to use the Block Intruder feature and drop the connection for 5 minutes. New connections are not allowed at that point until 0600.

Is there a way for the rule to drop active connections?  Or will I have to run some kind of script to accomplish this?

0 Kudos
2 Replies
Highlighted
Admin
Admin

You'll have to run some sort of script to do it.
It would probably be a fairly simple crontab using fw samp or similar.
0 Kudos
Highlighted

Agree with Phoneboy here that you will need to use a script, time ranges are only checked as a rule matching condition at connection start time, and never checked again once the connection is initially allowed.

Book "Max Power 2020: Check Point Firewall Performance Optimization" Third Edition
Now Available at www.maxpowerfirewalls.com
0 Kudos