Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ven
Participant

Firewall Deny Vs Drop

Hi Experts,

Firewall deny vs Firewall Drop.  Out of two which consumes cpu resources or affects GW performance when looked at during an DoS scenario ?  

 

0 Kudos
3 Replies
Marcel_Gramalla
Advisor

You mean "Block" vs "Drop" right? As block sends a connection refused it consumes more CPU and you can actually detect if there is something on that IP. Drop on the other hand just ends in a timeout.

Ven
Participant

yes, question is about Block" vs "Drop.  Thanks for your quick response and info

0 Kudos
_Val_
Admin
Admin

Neither Deny nor Block are used in FW Network Security rules. You probably mean "Reject", right?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events