- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
R81.10 latest JHF.
I would like to setup SYN Attack defence.
I read the KBs and guides and I see you need to set threshold limits, as it can be different from one environment to another and should be set carefully.
How do I know what values to use?
Where can I see average and peak numbers for these values?
Thanks
I see here 132 half opened out of 26k established, which is VERY good. Why would you think the default SYNAttack settings are too strict?
I would start with defaults and then see if they are okay for your specific needs, then adjust if required
Hi Val,
That's what I'm afraid of, that the defaults values are not suitable for our environment and that the SynAtk mechanism will kick in unnecessarily and block traffic.
I want to check see details about current or avarage connection requests and half-open TCP connections so I know if it's within the default threshold limits.
I tried CPVIEW but I'm not sure what to make out of this data:
Thanks
I see here 132 half opened out of 26k established, which is VERY good. Why would you think the default SYNAttack settings are too strict?
First, I wan't sure that Handshake Connections is the same as Half-Open connections, so thatnks for clearing that up.
Second, this screenshot represent the current state. Where can I see weekly or monthly avarage or peaks?
You can export the data from cpview (it's a sqlite DB, as I recall) and import it into whatever tool you'd like to create graphs/averages.
cpview only shows current state (or state at the chosen timestamp).
Thanks, I ended up just scrolling using '+' and '-' keys on the specific dates I know we have peak traffic 🙂
Next time...
Update -
I used CPVIEW -t to browse a month of history and saw the values don't change drastically.
I also understood that the Critical Performance hit rating isn't accurate on R81.10 (https://community.checkpoint.com/t5/Security-Gateways/Why-is-syn-attack-protection-disabled-on-the-i...)
I enabled the Synatk protection with default values on external interface only and so far so good.
Thanks for the help!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY