<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zone Protection Flood Protection Max Packets per Sec And new sessions per second values. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2866#M2119</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone help me understand the impact of enabling Flood Protection on legitimate connections. If I have a 3050 as an external firewall protecting a website having high transaction how do you make sure the TCP flood protection with "random drop" value set does not kill legitimate traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does is make any sense to have a flood protection value set to a value below the new sessions per second value of a firewall ?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;For example : the new sessions per second for 3050 is &lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;50,000 new sessions per second,&amp;nbsp; would you set a zone protection profile with flood protection enabled for 40000 packets per second ? would this not kill legitimate traffic ? and are you not limiting the capability of the appliance by doing this ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;Kind Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;Sunil &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 May 2013 19:47:38 GMT</pubDate>
    <dc:creator>sunilsadanandan</dc:creator>
    <dc:date>2013-05-03T19:47:38Z</dc:date>
    <item>
      <title>Zone Protection Flood Protection Max Packets per Sec And new sessions per second values.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2866#M2119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone help me understand the impact of enabling Flood Protection on legitimate connections. If I have a 3050 as an external firewall protecting a website having high transaction how do you make sure the TCP flood protection with "random drop" value set does not kill legitimate traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does is make any sense to have a flood protection value set to a value below the new sessions per second value of a firewall ?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;For example : the new sessions per second for 3050 is &lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;50,000 new sessions per second,&amp;nbsp; would you set a zone protection profile with flood protection enabled for 40000 packets per second ? would this not kill legitimate traffic ? and are you not limiting the capability of the appliance by doing this ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;Kind Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 11.333333015441895px; background-color: #ffffff;"&gt;Sunil &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 May 2013 19:47:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2866#M2119</guid>
      <dc:creator>sunilsadanandan</dc:creator>
      <dc:date>2013-05-03T19:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection Flood Protection Max Packets per Sec And new sessions per second values.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2867#M2120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is a good question. There is a very general document located here: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3094"&gt;https://live.paloaltonetworks.com/docs/DOC-3094&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does not really give best practices however. Almost everything I have ever read says "trial and error!" When I asked about best practices when we first set up our PAN, they recommended leaving the defaults until we analyzed session data and had a grasp on the environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Message was edited by: Corey Raymond&#xD;
&#xD;
If you are using IIS, I would recommend going through Microsoft's recommendations for hardening your TCP Stack located at :&#xD;
&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://msdn.microsoft.com/en-us/library/ff648853.aspx"&gt;http://msdn.microsoft.com/en-us/library/ff648853.aspx&lt;/A&gt;&lt;SPAN&gt;&#xD;
&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 May 2013 20:25:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2867#M2120</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-05-03T20:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection Flood Protection Max Packets per Sec And new sessions per second values.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2868#M2121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know if you have seen it yet, but a new document has been posted that goes a lot more in depth on setting DoS/Flood Protection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-5078"&gt;https://live.paloaltonetworks.com/docs/DOC-5078&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 20:27:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2868#M2121</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-05-10T20:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection Flood Protection Max Packets per Sec And new sessions per second values.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2869#M2122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is a good document , I think this part answers my question , from below we should read packets per second as new connections per second , i.e. if the servers you are protecting can handle the 50000 new connections per second and is protected by a 3050 , you would not need a Syn flood protection using RED to be below the 50000 capable by the 3050. Maybe slightly lesser , but not significantly lesser ? The case is different for Syn cookies as they are more precise on what they drop, i.e. they just drop sessions from clients that do not respond to SYN cookies , most likely spoofed ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"That means that the packets-per-second metric actually stands for new attempted sessions-per-second. For example in the case of SYN&lt;/P&gt;&lt;P&gt;floods, 10,000 pps means 10,000 new SYNs per second. The reason we mention this as pps and not cps (connections per&lt;/P&gt;&lt;P&gt;second) is because the session has not been created in the session table yet. It is a half connection"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 06:19:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2869#M2122</guid>
      <dc:creator>sunilsadanandan</dc:creator>
      <dc:date>2013-05-13T06:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection Flood Protection Max Packets per Sec And new sessions per second values.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2870#M2123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One thing that is not covered by Zone protection of course, is lower level DoS protection of particular servers, which will most likely have to be done at the policy level under the Dos Protection Profiles. So, if you are protecting your entire zone with specific DoS protection parameters, those may not be adequate for protecting a particular server in that zone. This also depends on how you "Zoned" in the first place, but there is also the DoS protection Profiles in the policies setup. You may have to create DoS protection profiles for particular web servers if the Zone DoS protection is not adequate. There are some built in mechanisms on most modern "Internet" servers, but you may find that these are not adequate protection against SYN floods and the like. The server's ability to work under heavy traffic also depends on system resources and configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 19:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2870#M2123</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2013-05-14T19:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection Flood Protection Max Packets per Sec And new sessions per second values.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2871#M2124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the easiest way to determine the Average Peak Traffic (packets per second) on the PA-200 so we can fine tune the Syn Flood settings for alert, activate, max?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 17:06:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-flood-protection-max-packets-per-sec-and-new/m-p/2871#M2124</guid>
      <dc:creator>Ebernardo</dc:creator>
      <dc:date>2014-02-13T17:06:51Z</dc:date>
    </item>
  </channel>
</rss>

