> Source: [sk183646](https://support.checkpoint.com/results/sk/sk183646)

# sk183646 - Security Gateway drops connections by "Implied Rule - enforce_net_quota"

| Property | Value |
|----------|-------|
| Solution ID | sk183646 |
| Date Created | 2025-07-10 |
| Last Modified | 2025-07-13 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Security Gateway logs in SmartConsole show that it drops connections from a specific source using "`Implied Rule 0`".

* After enabling the informative logs for implied rules ([sk110218](https://support.checkpoint.com/results/sk/sk110218)), the Security Gateway logs in SmartConsole show "`Implied Rule - enforce_net_quota`".

## Cause

When the IPS protection "Network Quota" is enabled, and the number of connections per second from the same source exceeds the configured limit, the Security Gateway drops new connections from the same source using the implied rule "`enforce_net_quota`".

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
