cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted
Nickel

FW Samp or penalty box

We have a number of AWS IP's hitting our GW's reglulaly with quite high connection rates on http and https (so can get through to our website).  Would you recommend using FW samp or Penalty box to deal with these type of attacks?

I have been warned against using Network quota as it has a major performance impact.


Thanks

Jon

0 Kudos
1 Reply
Highlighted

Re: FW Samp or penalty box

Yes avoid the IPS signature Network Quota as that will kill practically all SecureXL acceleration in the firewall.

SecureXL penalty box only applies to an hosts with an excessive drop/block rate, so it won't apply to accepted HTTP/HTTPS connections to your websites.

The fw samp command can establish various quotas for accepted traffic that are efficiently enforced by SecureXL; I'd suggest a new-conn-rate quota combined with "track source".  Check out sk112454: How to configure Rate Limiting rules for DoS Mitigation

 

Book "Max Power 2020: Check Point Firewall Performance Optimization" Third Edition
Now Available at www.maxpowerfirewalls.com
0 Kudos