- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
We keep hitting our max connections for "High Rate of Blocked Connections" within smart event > DOS. We have upped the limit for now but I would like to understand more on how this works?
I believe the default for this rule is Origin which is the firewall itself. When triggered what does the event do, it seems to reject connections on the top source, is this correct?
Does anyone else use this rule and could you advise on best practices for this rule or what other users settings are? for example: Should we change the distinct event candidates away from Origin?
I have looked at the admin guides but feel it doesnt explain what is actually happening.
Thanks
Jim
Maybe this can help: sk112454: How to configure Rate Limiting rules for DoS Mitigation
Thanks, I assume these are manual rules and not the Smart Event. I still am yet to understand the actual rule itself?
Can anyone share there settings for this rule or explain how it works?
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY