> Source: [sk97870](https://support.checkpoint.com/results/sk/sk97870)

# sk97870 - IPS protection "Network Quota" drops traffic from a host before the configured quota is reached

| Property | Value |
|----------|-------|
| Solution ID | sk97870 |
| Date Created | 2013-12-25 |
| Last Modified | 2016-03-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- SmartView Tracker logs from IPS show that "Network Quota" protection drops traffic from a host before the configured quota is reached.

*Example*:

```

Type: Log
Product: IPS
Protection Name: Network Quota
Severity: High
Protection Type: Protocol Anomaly
Industry Reference: CAN-2002-0957, CAN-2002-0629, CAN-2002-0957, CAN-2002-0629
Attack: Network Quota Violation
Attack Information: Network quota was exceeded
Action: Drop
```

## Cause

IPS protection "Network Quota" enforces a limit on the number of simultaneous connections that are allowed from the same source IP.

The number of connections per second defined in the IPS protection "Network Quota" applies to the entire Security Gateway.

On a Security Gateway with enabled CoreXL, a quota is managed for each individual CoreXL FW instance - each instance gets at least some small portion of the *global* quota limit that was configured.

At first, the initial portion of the quota for each CoreXL FW instance is calculated and allocated.

The rest of global quota is used as a "pool" of quotas that will be handed out to the CoreXL FW instances based on the need.

When a CoreXL FW instance reaches its allocated limit, it requests an additional allocation from the remaining global quota.

When that global quota is depleted, and CoreXL FW instance does not get additional quota, it will drop the connection.

If you want this IPS protection to drop the connections based exactly on the required limit, then, as a rule of thumb, define the quota of at least the "required number of connections per second + 10".

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
