{"id":1124,"date":"2019-03-19T16:18:49","date_gmt":"2019-03-19T16:18:49","guid":{"rendered":"http:\/\/www.ankenbrand24.de\/?page_id=1124"},"modified":"2019-03-19T16:21:33","modified_gmt":"2019-03-19T16:21:33","slug":"ddos-fw-sam-vs-fwaccel-dos","status":"publish","type":"page","link":"https:\/\/www.ankenbrand24.de\/index.php\/articles\/check-point-articel\/performance-tuning\/ddos-fw-sam-vs-fwaccel-dos\/","title":{"rendered":"DDoS fwaccel dos"},"content":{"rendered":"\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"message-subject\" style=\"text-align: center;\"><span class=\"lia-message-read\">R80.x Performance Tuning Tip \u2013 DDoS \u201efw sam\u201c vs. \u201efwaccel dos\u201c<\/span><\/h2>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">What is SecureXL penalty box?<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><img loading=\"lazy\" class=\"alignnone  wp-image-1125\" src=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_1.png\" alt=\"\" width=\"305\" height=\"177\" srcset=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_1.png 312w, https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_1-150x87.png 150w\" sizes=\"(max-width: 305px) 100vw, 305px\" \/><\/p>\n<p>The SecureXL penalty box is a mechanism that performs an early drop of packets arriving from suspected sources. This mechanism is supported starting in R75.40VS.<\/p>\n<p>Why not sam policy rules?<\/p>\n<p>The SAM policy rules consume some CPU resources on Security Gateway. We recommend to set an expiration that gives you time to investigate, but does not affect performance. The best practice is to keep only the SAM policy rules that you need. If you confirm that an activity is risky, edit the Security Policy, educate users, or otherwise handle the risk. Or better use SecureXL penalty box from a performance point of view.<\/p>\n<p>The purpose of this feature is to allow the Security Gateway to cope better under high load, possibly caused by a DoS\/DDoS attack. These commands \u201efwaccel dos\u201c and \u201efwaccel6 dos\u201c\u00a0 control the Rate Limiting for DoS mitigation techniques in SecureXL on the local security gateway or cluster member.<\/p>\n<p>In version R80.20, the penalty box feature is now supported in VSX mode and each virtual system can be independently configured for penalty box operation.<\/p>\n<p><strong>Attention!<\/strong><\/p>\n<p>In R80.20, all &#8220;sim erdos&#8221; commands are no longer supported. They have been replaced with equivalent commands which can be found under &#8220;fwaccel dos&#8221;. Penalty box is configured separately for IPv4 and IPv6. IPv4 configuration is performed using the &#8220;fwaccel dos&#8221; command. IPv6 configuration is performed using the &#8220;fwaccel6 dos&#8221; command.<\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">Old known SAM rule<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p>This would be a classic SAM rule which already existed in all versions R77.30, R80.10 and R80.20. In this example the source IP 1.2.3.4 is blocked.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-1126\" src=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_2.png\" alt=\"\" width=\"605\" height=\"187\" srcset=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_2.png 605w, https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_2-150x46.png 150w\" sizes=\"(max-width: 605px) 100vw, 605px\" \/><\/p>\n<p>I don&#8217;t want to go into the SAM rules further here. You can read it here: <a class=\"link-titled\" title=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk112061#Creating%20a%20New%20Suspicious%20Activity%20Rule\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk112061#Creating%20a%20New%20Suspicious%20Activity%20Rule\" target=\"_blank\" rel=\"noopener noreferrer\">How to create and view Suspicious Activity Monitoring (SAM) Rules<\/a>.<\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">IP blacklist<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><span style=\"color: #33cccc; font-size: 22px;\"><strong>Tip 1<br \/><\/strong><\/span>Controls the IP blacklist in SecureXL. The blacklist blocks all <span style=\"color: black;\">traffic<\/span> to and from the specified IP addresses. It is an easy way to block certain IP addresses quickly and eficiently on SecureXL level.<\/p>\n<p>The blacklist drops occur in SecureXL, which is more efficient than an Access Control Policy or SAM rule to drop the packets. This can be very helpful e.g. with DoS attacks to block an IP on SecureXL level.<\/p>\n<p>For example, the traffic from and to IP 1.2.3.4 should be blocked at SecureXL level.<\/p>\n<p>On gateway set the IP 1.2.3.4 to Secure XL blacklist:<\/p>\n<p><span style=\"font-size: 11.0pt;\"># <span style=\"color: red;\"><strong>fwaccel dos blacklist -a 1.2.3.4<\/strong><\/span><strong><br \/><img loading=\"lazy\" class=\"alignnone size-full wp-image-1127\" src=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_3.png\" alt=\"\" width=\"486\" height=\"46\" srcset=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_3.png 486w, https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_3-150x14.png 150w\" sizes=\"(max-width: 486px) 100vw, 486px\" \/><br \/><\/strong><\/span><\/p>\n<p>On gateway displays all IP&#8217;s on the SecureXL blacklist:<\/p>\n<p># <span style=\"color: red;\"><strong>fwaccel dos blacklist -s<\/strong><\/span><\/p>\n<p><strong><img loading=\"lazy\" class=\"alignnone size-full wp-image-1128\" src=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_4.png\" alt=\"\" width=\"487\" height=\"43\" srcset=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_4.png 487w, https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_4-150x13.png 150w\" sizes=\"(max-width: 487px) 100vw, 487px\" \/><\/strong><\/p>\n<p>On gateway delete the IP 1.2.3.4 from Secure XL blacklist:<\/p>\n<p>#\u00a0 <span style=\"color: red;\"><strong>fwaccel dos blacklist -d 1.2.3.4<\/strong><\/span><\/p>\n<p><strong><img loading=\"lazy\" class=\"alignnone size-full wp-image-1129\" src=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_5.png\" alt=\"\" width=\"487\" height=\"42\" srcset=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_5.png 487w, https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/ddos_5-150x13.png 150w\" sizes=\"(max-width: 487px) 100vw, 487px\" \/><\/strong><\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">Penalty Box<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><span style=\"color: #33cccc; font-size: 22px;\"><strong>Tip 2<br \/><\/strong><\/span>Controls the Penalty Box whitelist in SecureXL.<\/p>\n<p class=\"\">The SecureXL Penalty Box is a mechanism that performs an early drop of packets that arrive from suspected sources. The purpose of this feature is to allow the Security Gateway to cope better under high traffic load, possibly caused by a DoS\/DDoS attack. The SecureXL Penalty Box detects clients that sends packets, which the Access Control Policy drops, and clients that violate the IPS protections. If the SecureXL Penalty Box detect a specific client frequently, it puts that client in a penalty box. From that point, SecureXL drops all packets that arrive from the blocked source IP address.<\/p>\n<p class=\"\">The Penalty Box whitelist in SecureXL lets you configure the source IP addresses, which the SecureXL Penalty Box never blocks. <a title=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk74520&amp;partition=Advanced&amp;product=SecureXL%22\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk74520&amp;partition=Advanced&amp;product=SecureXL%22\" target=\"_blank\" rel=\"noopener noreferrer\">What is the SecureXL penalty box mechanism for offending IP addresses?<\/a>\u00a0<\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">Penalty Box whitelist<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><span style=\"color: #33cccc; font-size: 22px;\"><strong>Tip 3<br \/><\/strong><\/span>Furthermore there are also the Penalty Box whitelist in SecureXL.<\/p>\n<p>The SecureXL Penalty Box is a mechanism that performs an early drop of packets that arrive from suspected sources. The purpose of this feature is to allow the Security Gateway to cope better under high traffic load, possibly caused by a DoS\/DDoS attack. The SecureXL Penalty Box detects clients that sends packets, which the Access Control Policy drops, and clients that violate the IPS protections. If the SecureXL Penalty Box detect a specific client frequently, it puts that client in a penalty box. From that point, SecureXL drops all packets that arrive from the blocked source IP address. The Penalty Box whitelist in SecureXL lets you configure the source IP addresses, which the SecureXL Penalty Box never blocks.<\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">References<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><a class=\"link-titled\" title=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk74520&amp;partition=Advanced&amp;product=SecureXL%22\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk74520&amp;partition=Advanced&amp;product=SecureXL%22\" target=\"_blank\" rel=\"noopener noreferrer\">What is the SecureXL penalty box mechanism for offending IP addresses?<\/a>\u00a0<br \/><a class=\"link-titled\" title=\"https:\/\/sc1.checkpoint.com\/documents\/R80.20_GA\/WebAdminGuides\/EN\/CP_R80.20_CLI_ReferenceGuide\/html_frameset.htm?topic=documents\/R80.20_GA\/WebAdminGuides\/EN\/CP_R80.20_CLI_ReferenceGuide\" href=\"https:\/\/sc1.checkpoint.com\/documents\/R80.20_GA\/WebAdminGuides\/EN\/CP_R80.20_CLI_ReferenceGuide\/html_frameset.htm?topic=documents\/R80.20_GA\/WebAdminGuides\/EN\/CP_R80.20_CLI_ReferenceGuide\" target=\"_blank\" rel=\"noopener noreferrer\">Command Line Interface R80.20 Reference Guide<\/a>\u00a0<br \/><a class=\"link-titled\" title=\"https:\/\/sc1.checkpoint.com\/documents\/R80.20_GA\/WebAdminGuides\/EN\/CP_R80.20_PerformanceTuning_AdminGuide\/html_frameset.htm\" href=\"https:\/\/sc1.checkpoint.com\/documents\/R80.20_GA\/WebAdminGuides\/EN\/CP_R80.20_PerformanceTuning_AdminGuide\/html_frameset.htm\" target=\"_blank\" rel=\"noopener noreferrer\">Performance Tuning R80.20 Administration Guide<\/a>\u00a0<br \/><a class=\"link-titled\" title=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk112061#Creating%20a%20New%20Suspicious%20Activity%20Rule\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk112061#Creating%20a%20New%20Suspicious%20Activity%20Rule\" target=\"_blank\" rel=\"noopener noreferrer\">How to create and view Suspicious Activity Monitoring (SAM) Rules<\/a>\u00a0<\/p>\n<p>Copyright by <a href=\"\/migrated-users\/55229\" target=\"_blank\" rel=\"noopener noreferrer\">Heiko Ankenbrand<\/a>\u00a0 1994-2019<\/p>\n","protected":false},"excerpt":{"rendered":"<p>R80.x Performance Tuning Tip \u2013 DDoS \u201efw sam\u201c vs. \u201efwaccel dos\u201c What is SecureXL penalty box? The SecureXL penalty box is a mechanism that performs an early drop of packets arriving from suspected sources. This mechanism is supported starting in R75.40VS. Why not sam policy rules? The SAM policy rules consume some CPU resources on<\/p>\n<p><a class=\"button\" href=\"https:\/\/www.ankenbrand24.de\/index.php\/articles\/check-point-articel\/performance-tuning\/ddos-fw-sam-vs-fwaccel-dos\/\" title=\"More\">  Read More \u2192<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":1068,"menu_order":6,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages\/1124"}],"collection":[{"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/comments?post=1124"}],"version-history":[{"count":3,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages\/1124\/revisions"}],"predecessor-version":[{"id":1132,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages\/1124\/revisions\/1132"}],"up":[{"embeddable":true,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages\/1068"}],"wp:attachment":[{"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/media?parent=1124"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}