> Source: [sk111881](https://support.checkpoint.com/results/sk/sk111881)

# sk111881 - Rate Limiting rules for DoS Mitigation are not taking effect

| Property | Value |
|----------|-------|
| Solution ID | sk111881 |
| Date Created | 2016-06-14 |
| Last Modified | 2018-12-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Rate Limiting rules for DoS Mitigation ("fw samp" per [sk112454](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112454)) are not enforced correctly. Connections are still going through beyond the configured threshold.

* Output of `fw samp get -l | grep '^<[0-9a-f,]*>$' | xargs sim_dos get` command shows that there are active Rate Limiting rules.

  Note: in R80.20, the command is `fw samp get -l | grep '^<[0-9a-f,]*>$' | xargs fwaccel dos rate get`
* Output of *fw tab -t connections -u \| grep RELEVANT_SOURCE_IP \| grep (port 443)* command shows that there are more than 2 connections for the particular pair of hosts.

* Connections are originating from the Internal side of the Security Gateway, or the topology is defined so that the connections are Internal-to-External or Internal-to-Internal.

## Cause

By default, Rate Limiting rules for DoS Mitigation are defined to prevent External-to-Internal traffic. These rules will not enforce Internal-to-External or Internal-to-Internal connections.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
