QuestionQ4

Advanced Troubleshooting Techniques

The customer uses Check Point appliances that were configured long ago by third-party administrators. The current policy contains various enabled IPS protections and the Bypass Under Load function. Bypass Under Load is set to disable IPS inspections when CPU and memory usage is above 80%.

The customer reports that IPS protections do not work at all, irrespective of CPU and memory usage. What could cause this behavior?

  • A The kernel parameter ids_assume_stress is set to 0
  • B The kernel parameter ids_assume_stress is set to 1
  • C The kernel parameter ids_tolerance_no_stress is set to 10
  • D The kernel parameter ids_tolerance_stress is set to 10
Explanation

Setting ids_assume_stress to 1 makes the IPS engine assume the gateway is under load. With Bypass Under Load enabled, IPS inspection is therefore bypassed continuously instead of only after CPU or memory usage exceeds 80%.

Community Discussion

No comments yet. Be the first to start the discussion!