<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to limit concurrent session per source IP? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-limit-concurrent-session-per-zone-or-per/m-p/19641#M14342</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;BR /&gt;I have just a small question about the DoS profile, for a test I configured the profile with the value below for Syn flood:&lt;/P&gt;&lt;P&gt;Alarm Rate (packets/sec) 50&lt;BR /&gt;Activate Rate (packets/sec) 50&lt;BR /&gt;Maximal Rate (packets/sec) 800&lt;BR /&gt;Block Duration (seconds) 300&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After flooding with 100pps I can see on the threat log that syn flood was detected and randomly was dropped, but how about the first value (Alarm Rate) where I should receive the Alarm ? as above I should receive an alarm after 50pps ?&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Nov 2012 15:23:15 GMT</pubDate>
    <dc:creator>BSadozai</dc:creator>
    <dc:date>2012-11-29T15:23:15Z</dc:date>
    <item>
      <title>Is it possible to limit concurrent session per Zone or per source IP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-limit-concurrent-session-per-zone-or-per/m-p/19638#M14339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys.&lt;/P&gt;&lt;P&gt;I was looking to limit session per Zone or per src IP and I found this discussion, so we are in version 4.1.8 and cannot find any option on the QoS to do this limit ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2012 16:05:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-limit-concurrent-session-per-zone-or-per/m-p/19638#M14339</guid>
      <dc:creator>BSadozai</dc:creator>
      <dc:date>2012-11-22T16:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to limit concurrent session per source IP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-limit-concurrent-session-per-zone-or-per/m-p/19639#M14340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is not under the QoS setting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To do this, you need to go to the policy tab and configure the DoS policy. You need to input the source and destination zones you want to apply the control, and choose&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- protect instead of allow/any as the action&lt;/P&gt;&lt;P&gt;- classified instead of aggregated as the type of protection&lt;/P&gt;&lt;P&gt;- choose whether you want to consider a counter hit by just the src IP, src IP + Dst IP or just the dst IP&lt;/P&gt;&lt;P&gt;- create the DoS profile, and under the resource protection input the limit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jones&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2012 16:30:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-limit-concurrent-session-per-zone-or-per/m-p/19639#M14340</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2012-11-22T16:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to limit concurrent session per source IP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-limit-concurrent-session-per-zone-or-per/m-p/19640#M14341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for your quick answer.&lt;/P&gt;&lt;P&gt;This is greate.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2012 08:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-limit-concurrent-session-per-zone-or-per/m-p/19640#M14341</guid>
      <dc:creator>BSadozai</dc:creator>
      <dc:date>2012-11-23T08:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to limit concurrent session per source IP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-limit-concurrent-session-per-zone-or-per/m-p/19641#M14342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;BR /&gt;I have just a small question about the DoS profile, for a test I configured the profile with the value below for Syn flood:&lt;/P&gt;&lt;P&gt;Alarm Rate (packets/sec) 50&lt;BR /&gt;Activate Rate (packets/sec) 50&lt;BR /&gt;Maximal Rate (packets/sec) 800&lt;BR /&gt;Block Duration (seconds) 300&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After flooding with 100pps I can see on the threat log that syn flood was detected and randomly was dropped, but how about the first value (Alarm Rate) where I should receive the Alarm ? as above I should receive an alarm after 50pps ?&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 15:23:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-limit-concurrent-session-per-zone-or-per/m-p/19641#M14342</guid>
      <dc:creator>BSadozai</dc:creator>
      <dc:date>2012-11-29T15:23:15Z</dc:date>
    </item>
  </channel>
</rss>

