- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Can Checkpoint 5200 PB-20 IPS can inspect Mysq...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can Checkpoint 5200 PB-20 IPS can inspect Mysql packets?
Can Checkpoint 5200 PB-20 IPS assess the content from incoming packets for Mysql database server (port 3306)? If the packet is according to a real Mysql packet then this can be forwarded to the database server, otherwise it will be dropped. The idea is to avoid DDOS attacks by sending massive TCP connections to Mysql server by Telnet or another application.
- Labels:
-
Checkpoint
-
DDOS ATTACK
-
firewall
-
IPS
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Review the IPS Protections for yourself to see what will be blocked.
What is your precise definition of “massive TCP connections”?
If you’re concerned about that happening, you can use the ratelimiting functions.
See: https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-DDoS-fw-sam-vs-fwacc...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, it can.
However, I’m curious why the concern about DDoS since a MySQL server should only be accessed from specific hosts, not generally accessible from the Internet.
While we can do some rate limiting and such if required, if you’re really concerned about DDoS, Check Point sells specific solutions for this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My suspect it's not about someone from outside but It's someone from inside who can execute it from these specific hosts even.
I have the following questions:
1) By customizing Threat Prevention with IPS would help in case of malformed mysql packets?
2) There is an option of 'IPS Protections' from SmartConsole. Can one of these protections match about the case I explained?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Review the IPS Protections for yourself to see what will be blocked.
What is your precise definition of “massive TCP connections”?
If you’re concerned about that happening, you can use the ratelimiting functions.
See: https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-DDoS-fw-sam-vs-fwacc...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the picture and the link.
What is your precise definition of “massive TCP connections”?
- I mean multiple TCP connections. I tried to mention it as a synonym. These connections are associated with packets.
