> Source: [sk102909](https://support.checkpoint.com/results/sk/sk102909)

# sk102909 - Recommendations for DDoS Protector while under DoS attack

| Property | Value |
|----------|-------|
| Solution ID | sk102909 |
| Date Created | 2014-10-28 |
| Last Modified | 2016-07-18 |
| Technical Level | General |

## Solution

The following steps should be done if services are n?t available due to DDoS attack

* Make sure all your security policies are in "Block and Report" mode.  

* Make sure you are running the latest software version.  

* Make sure you have installed the latest attack database (signatures).  

* Ensure that Network Protection policies are well defined and include all your network IP ranges.  

* Make sure you have the "DoS-All" Signature Profile at a minimum enabled in your active network policy. In addition, a "BDoS" profile should also be assigned to the polices.  

* Enable a connection limit (on HTTP/S), set the �Tracking Type� to �Source Count� and �Action Mode� to "Drop".   
  Note this is in Connections per second per source IP address, so you should set the �Number of Connections� you think reasonable for your network.   

* Lower your SYN protection �Activation� (100) and �Termination� (50) thresholds.   

* Lower the strictness level on the BDoS, HTTP mitigator and DNSprofiles  

* Take packet captures - this is VERY important.  
  Take the real time packet captures; It does not have to be a state of the art capture monster, even a PC running Wireshark connected to a mirror port on the router will do. Prepared in advance and educate your personnel on running it, in case of attack that evades current protection it is going the most useful way to gather information

**Related solutions**:

* [sk102908 - How to access DDoS Protector Emergency Response Team (ERT) while under DoS attack](http://supportcontent.checkpoint.com/solutions?id=sk102908)
* [sk108208: Best Practices - DDoS Protector](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108208)
* [sk112241: Best Practices - DDoS attacks on Check Point Security Gateway caused by Vulnerability/Port Scanners](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112241)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
