<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Flood protection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/127840#M46621</link>
    <description>&lt;P&gt;What is the best way to set up flood protection, separate profile one for ICMP, one for SYN cookies etc or put it all in one policie? What is the best way to determine what set your alarm rates, block rate etc? How successful is it, does good traffice get blocked very much&lt;/P&gt;</description>
    <pubDate>Mon, 21 Nov 2016 16:01:52 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2016-11-21T16:01:52Z</dc:date>
    <item>
      <title>Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/127840#M46621</link>
      <description>&lt;P&gt;What is the best way to set up flood protection, separate profile one for ICMP, one for SYN cookies etc or put it all in one policie? What is the best way to determine what set your alarm rates, block rate etc? How successful is it, does good traffice get blocked very much&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2016 16:01:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/127840#M46621</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-21T16:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/127900#M46625</link>
      <description>&lt;P&gt;I also see that there is zone protection and it looks very similar to flood protection, so which one is better?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2016 19:05:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/127900#M46625</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-21T19:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/127977#M46627</link>
      <description>&lt;P&gt;I would go with Dos Protection profile and setup Dos Security Policy. As far as denying traffic it will depend on what "action " you choose when creating Dos proection policy there are 3 options Allow,Deny, Protect.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 00:09:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/127977#M46627</guid>
      <dc:creator>clyde.franklin</dc:creator>
      <dc:date>2016-11-22T00:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128041#M46631</link>
      <description>&lt;P&gt;zone protection is the broad-stroke protection of an interface, regardless of the source-destination pair. it allows you to set up 'expected' flows and take action when your , for example, external interface comes under attack by enforcing syn cookies or dropping packets once a certain volume is reached&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dos protection policies are there to protect specific resources. you can limit or regulate the flow towards a specific ip address&lt;/P&gt;
&lt;P&gt;this comes in handy when for example your internet pipe throughput is much larger than one certain asset you want to protect, you can then finetine your protection to cater to specific servers while not limiting your overall throughput&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 08:21:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128041#M46631</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-22T08:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128134#M46643</link>
      <description>&lt;P&gt;I think that I want something more granular so I believe I will go with the DoS protection profile. I am currently in the process of deciding the best alarm rate, activate rate, max rate and block duration. I have some specific security policies using ICMP that I want to start with and then go from there.&amp;nbsp; I did a calculation based on my highest session numbers the result is very close to the limitation of 2,000,000 in the profile. So are you using this and how is it working for you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11/13/2016 – 101.64M \7 days = 14.52M/day \86400 seconds in a day = 1.68M per sec&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 14:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128134#M46643</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-22T14:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128163#M46653</link>
      <description>&lt;P&gt;So the profile cannot just be added to a security policy, you have to create a DoS policy to put on the security policies&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 15:30:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128163#M46653</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-22T15:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128170#M46654</link>
      <description>&lt;P&gt;So you can't just apply a DoS profile to an existing security policies you have to create a DoS security policy, add a DoS protection profile and then add it to a security policies&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 15:32:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128170#M46654</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-22T15:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128178#M46656</link>
      <description>&lt;P&gt;no, the DoS protection policies are independent from security policies, much like the QoS policies&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You first create a profile and then a (DoS) policy to match an expected flow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 15:41:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128178#M46656</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-22T15:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128194#M46658</link>
      <description>&lt;P&gt;So it affects everything? You can't just apply it to specific security policies?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 15:51:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128194#M46658</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-22T15:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128215#M46669</link>
      <description>&lt;P&gt;Along the same lines, so I am going to fashion my DoS policy based on the security rule that I want to affect, I assume that will work&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 17:18:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128215#M46669</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-22T17:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128229#M46670</link>
      <description>&lt;P&gt;What log do the alarms go too? This is what profile I am going to start out with for icmp and icmpv6, I tried to base this on my current network highest session count&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ICMP Flood and ICMVPv6 Flood&lt;BR /&gt;Alarm rate = 164 pps&lt;BR /&gt;Activate rate = 185.83 pps&lt;BR /&gt;Max rate = default (40000)&lt;BR /&gt;Block duration = default (300)&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 17:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128229#M46670</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-22T17:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128283#M46677</link>
      <description>&lt;P&gt;Can you set activate to 0 so it acts like an alert for testing the rule&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 19:29:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128283#M46677</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-22T19:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128390#M46688</link>
      <description>&lt;P&gt;the logs should appear in 'threat' log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you set activate at 0, you will start blocking (or 'taking action' to put it better, for syn-cookies this is actually a preferred setting where random early drop would &amp;nbsp;be better suited with a much higher activate) immediately, setting the 'alert' to&amp;nbsp;0 will immediately start producing logs but not taking actions just yet.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 08:24:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128390#M46688</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-23T08:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128467#M46705</link>
      <description>&lt;P&gt;So setting alert to 0 would be a good way to test if its working?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 14:29:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128467#M46705</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-23T14:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128470#M46706</link>
      <description>&lt;P&gt;yes &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 14:33:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/128470#M46706</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-23T14:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Flood protection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/129135#M46744</link>
      <description>&lt;P&gt;this is a great thread. &amp;nbsp;Loved reading it learning more about both of these features and their practicle implementation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2016 00:55:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flood-protection/m-p/129135#M46744</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-11-28T00:55:30Z</dc:date>
    </item>
  </channel>
</rss>

