> Source: [sk102908](https://support.checkpoint.com/results/sk/sk102908)

# sk102908 - How to access DDoS Protector Emergency Response Team (ERT) while under DoS attack

| Property | Value |
|----------|-------|
| Solution ID | sk102908 |
| Date Created | 2014-10-28 |
| Last Modified | 2016-07-18 |
| Technical Level | General |

## Solution

**Contact Emergency Response Team (ERT):**

[Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) (also by phone) to open a *Severity 1 - Critical* issue with the following information:

1. "I have a DDoS Protector with Base MAC address x.x.x.x. The solution is deployed in my production network and I am currently under a DoS attack that is not mitigated by the DDoS Protector. My public services are down and I do not have access to internet. I need immediate assistance of the ERT."
2. Note the relevant servers that are being attacked.
3. Upload packet captures.
4. Provide network Diagram / Topology.
5. Download the device support file from the WebUI and attach it to the SR:  
   *File \> Support \> Download support file*.

**Action Plan:**

* Based on this information, Check Point Support (TAC) will contact ERT, while the customer is waiting on the phone and then establish a conference call between ERT, TAC and the customer.  

* Customer also needs to be able to provide remote access to DDoS Protector in those situations. This is easily done by the customer, if he connects to Internet from his laptop over a 3G connection and at the same time uses WLAN or LAN to connect to the DDoS Protector. The ERT can remotely control the customer DDoS Protector.  

* If the SR is opened over the Web, then call TAC as soon as you have a SR number and refer to the SR number.

**Related solutions**:

* [sk102909: Recommendations for DDoS Protector while under DoS attack](http://supportcontent.checkpoint.com/solutions?id=sk102909)
* [sk108208: Best Practices - DDoS Protector](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108208)
* [sk112241: Best Practices - DDoS attacks on Check Point Security Gateway caused by Vulnerability/Port Scanners](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112241)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
