- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Firewall Deny Vs Drop
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Firewall Deny Vs Drop
Hi Experts,
Firewall deny vs Firewall Drop. Out of two which consumes cpu resources or affects GW performance when looked at during an DoS scenario ?
3 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You mean "Block" vs "Drop" right? As block sends a connection refused it consumes more CPU and you can actually detect if there is something on that IP. Drop on the other hand just ends in a timeout.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes, question is about Block" vs "Drop. Thanks for your quick response and info
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Neither Deny nor Block are used in FW Network Security rules. You probably mean "Reject", right?
