<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DDoS Profiles in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ddos-profiles/m-p/585529#M3090</link>
    <description>&lt;P&gt;Do you need the full version of AI-OPs to achieve this?&lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2024 15:17:42 GMT</pubDate>
    <dc:creator>S_Williams901</dc:creator>
    <dc:date>2024-05-01T15:17:42Z</dc:date>
    <item>
      <title>DDoS Profiles</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ddos-profiles/m-p/584368#M3024</link>
      <description>&lt;P&gt;How does one go about getting the realistic values for your environment to plug into the DDoS profile or even the zone protection profile? How do you see how many SYNs you are getting per second/min etc?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 19:48:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ddos-profiles/m-p/584368#M3024</guid>
      <dc:creator>S_Williams901</dc:creator>
      <dc:date>2024-04-19T19:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: DDoS Profiles</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ddos-profiles/m-p/584670#M3045</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you referring to the DoS protection profiles or the Zone Protection settings? For the zone protection piece you could use AI-OPs and it will provide recommendations based on traffic. If you dont have AI-OPs, for both options would recommend setting the alarm value to a somewhat low value and see what triggers the alert and move it up from there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a snippet from the Palo doc:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;If you know the baseline CPS rates for the zone, use these guidelines to set the initial thresholds, and then monitor and adjust the thresholds as necessary.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Alarm Rate&lt;/DIV&gt;
—The new CPS threshold to trigger an alarm. Target setting the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;Alarm Rate&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to 15-20% above the average CPS rate for the zone so that normal fluctuations don’t cause alerts.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Activate&lt;/DIV&gt;
—The new CPS threshold to activate the flood protection mechanism and begin dropping new connections. For ICMP, ICMPv6, UDP, and other IP floods, the protection mechanism is Random Early Drop (RED, also known as Random Early Detection). For SYN floods only, you can set the drop&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;Action&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to SYN Cookies or RED. Target setting the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;
&lt;DIV&gt;Activate&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;rate to just above the peak CPS rate for the zone to begin mitigating potential floods.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Maximum&lt;/DIV&gt;
—The number of connections-per-second to drop incoming packets when RED is the protection mechanism. Target setting the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;Maximum&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rate to approximately 80-90% of firewall capacity, taking into account other features that consume firewall resources.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;DIV class="p"&gt;If you don’t know the baseline CPS rates for the zone, start by setting the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Maximum&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;CPS rate to approximately 80-90% of firewall capacity and use it to derive reasonable flood mitigation alarm and activation rates. Set the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Alarm Rate&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Activate&amp;nbsp;&lt;/SPAN&gt;rate based on the Maximum rate. For example, you could set the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Alarm Rate t&lt;/SPAN&gt;o half the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Maximum&amp;nbsp;&lt;/SPAN&gt;rate and adjust it depending on how many alarms you receive and the firewall resources being consumed. Be careful setting the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Activate Rate&amp;nbsp;&lt;/SPAN&gt;since it begins to drop connections. Because normal traffic loads experience some fluctuation, it’s best not to drop connections too aggressively. Err on the high side and adjust the rate if firewall resources are impacted.&lt;/DIV&gt;
&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p"&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/zone-protection-and-dos-protection/zone-defense/zone-protection-profiles/flood-protection" target="_blank"&gt;Flood Protection (paloaltonetworks.com)&lt;/A&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 23 Apr 2024 18:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ddos-profiles/m-p/584670#M3045</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-04-23T18:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: DDoS Profiles</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ddos-profiles/m-p/585529#M3090</link>
      <description>&lt;P&gt;Do you need the full version of AI-OPs to achieve this?&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 15:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ddos-profiles/m-p/585529#M3090</guid>
      <dc:creator>S_Williams901</dc:creator>
      <dc:date>2024-05-01T15:17:42Z</dc:date>
    </item>
  </channel>
</rss>

