Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Limit number of connections from one IP to checkpoint

Jump to solution

Hello Checkmate,

 

I have a Checkpoint R80.10 facing to internet. I saw a lot of connections to my webserver behind CP in smart console log like this:

connection.png

 

My question is how I can rate the number of connections of above IP , for example: when it already has 20 connections , a connection of 21th coming will be droped?

Thank a lot !!

 

 

 

0 Kudos
1 Solution

Accepted Solutions
Highlighted

First off, do NOT use the IPS signature "Network Quota" to do this as it will prevent practically all traffic from being accelerated on the firewall.

The best place to enforce rate limits is from SecureXL and is done from the firewall CLI, check out the "fw samp" command (R80.10 and earlier) and the "fwaccel dos rate/fw sam_policy" commands (R80.20+).

 

R80.40 addendum for book "Max Power 2020" now available
for free download at http://www.maxpowerfirewalls.com

View solution in original post

0 Kudos
1 Reply
Highlighted

First off, do NOT use the IPS signature "Network Quota" to do this as it will prevent practically all traffic from being accelerated on the firewall.

The best place to enforce rate limits is from SecureXL and is done from the firewall CLI, check out the "fw samp" command (R80.10 and earlier) and the "fwaccel dos rate/fw sam_policy" commands (R80.20+).

 

R80.40 addendum for book "Max Power 2020" now available
for free download at http://www.maxpowerfirewalls.com

View solution in original post

0 Kudos