> Source: [sk121754](https://support.checkpoint.com/results/sk/sk121754)

# sk121754 - Track Level Settings in IPS protection "Syn Attack" 

| Property | Value |
|----------|-------|
| Solution ID | sk121754 |
| Date Created | 2017-11-30 |
| Last Modified | 2020-09-09 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Solution

IPS protection "Syn Attack" includes in Logging Options Track level: "Attacks only" and "Individual SYN's."

**Attack Only** - An alert will be received when the SYN-per-second threshold is reached and SYN attack protection is engaged.

**Individual SYN's** - This setting will log each SYN that timed out so you can see there sources. You will also observe an alert when the SYN threshold is met as well as another alert when it subsides (**This may cause high CPU**).

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1512035278858/SynAttackLoggingSettingsSK1711300151.png)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
