- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
Background: We have 15600 Next Generation Firewall (in HA). We have an AD Server where we have different category of users (like faculty, staff, students) and also we have our Radius Server to meet the SSO requirements.
Objective:
How do we proceed in this case? Do we have any API or script handy or is there any other mechanism?
Regards,
Sudeep
What you are describing sounds a lot more like the function of a dedicated QoS system rather than what a typical firewall might be able to provide. The Check Point QoS blade (weights, limits, guarantees, LLQ, DiffServ) and Application Control bandwidth limit capabilities do not really have long-term monitoring capabilities; they are more about immediate management of bandwidth.
I suppose one could parse all firewall Accounting logs on some kind of third-party system and keep running totals of bandwidth utilization per user, utilize the fw samp/sim_dos commands on the firewall to start limiting individuals that have gone over their limit for the month, and then clear those imposed limits at the start of a new month. So yes there is a mechanism for enforcement on the Check Point once someone goes over the monthly limit, but not really a long-term monitoring mechanism to determine when someone has gone "over" and to punish them accordingly. 🙂
--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com
Thanks for your response.
but not really a long-term monitoring mechanism to determine when someone has gone "over" and to punish them accordingly. 🙂
By the way what is your recommendation to achieve my requirement. Please help and guide me.
What you are looking for is the comprehensive traffic shaping solution.
Those are outside of the scope of services that Check Point provides.
Some of it capabilities are present in Cisco, but I am not sure how flexible those are or if they could be user specific.
Simple, but a bit limited, is the Meraki offering on their switches, MX and MR devices.
Look up "traffic shaping" in Google and see what your options are.
Hi,
as supposed by Timothy above I had the need to grant the download limitation at 5 Mbps per user IP.
I did the following command, verify if it helps:
fw samp -a d -l r -n WIFI_5Mbps -c Limit_5Mbps service any source cidr:192.168.0.0/16 pkt-rate 625000 track source flush true
Sincerely.
Tiago Marques.
Hello, I have the same requirement, If you achieve your requirement then, It would be nice if you could share your solution.
Thanks,
RC
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY