Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
minhhaivietnam
Collaborator
Jump to solution

Limit number of connections from one IP to checkpoint

Hello Checkmate,

 

I have a Checkpoint R80.10 facing to internet. I saw a lot of connections to my webserver behind CP in smart console log like this:

connection.png

 

My question is how I can rate the number of connections of above IP , for example: when it already has 20 connections , a connection of 21th coming will be droped?

Thank a lot !!

 

 

 

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Legend Legend
Legend

First off, do NOT use the IPS signature "Network Quota" to do this as it will prevent practically all traffic from being accelerated on the firewall.

The best place to enforce rate limits is from SecureXL and is done from the firewall CLI, check out the "fw samp" command (R80.10 and earlier) and the "fwaccel dos rate/fw sam_policy" commands (R80.20+).

 

Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm

View solution in original post

0 Kudos
1 Reply
Timothy_Hall
Legend Legend
Legend

First off, do NOT use the IPS signature "Network Quota" to do this as it will prevent practically all traffic from being accelerated on the firewall.

The best place to enforce rate limits is from SecureXL and is done from the firewall CLI, check out the "fw samp" command (R80.10 and earlier) and the "fwaccel dos rate/fw sam_policy" commands (R80.20+).

 

Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events