<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone protection  - alert only in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199329#M59085</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another section of zone protection with no alert setting&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noalert.PNG" style="width: 288px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13694iA2344BF01FC71BB8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="noalert.PNG" alt="noalert.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Feb 2018 13:51:28 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2018-02-07T13:51:28Z</dc:date>
    <item>
      <title>Zone protection  - alert only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199144#M59049</link>
      <description>&lt;P&gt;I have been investigating zone&amp;nbsp; protection and DoS protection for awhile now and I think I would have already implemented it if you could configure all the settings to alert when you begin testing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 21:36:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199144#M59049</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-06T21:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection  - alert only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199260#M59070</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you look at zone protection there's always 3 values: alert, activate and maximum&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the alert setting is what does what you would like&lt;/P&gt;
&lt;P&gt;the maximum is the murder switch, so you'll want to stay away from that until you are confortable, and the activate is an interesting toggle, depending on your choice of action (RED or cookies)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the maximum will effectively cut off new sessions&lt;/P&gt;
&lt;P&gt;RED (random early drop) is a legacy method of randomly discarding incoming syn packets in an attempt to stifle/slow down connectio nrates and save resources&lt;/P&gt;
&lt;P&gt;SYN cookies are a cool method where each syn reqyest is answered with a cookie, which is a sort of mathematical little puzzle the client needs to answer. the session is not allocated in the session table until the client replies with the correct answer to the cookies&lt;/P&gt;
&lt;P&gt;so, random early drop needs to be set at a rate as close to your maximum as possible, syn cookies can be activated at 0 as this is a friendly deterrent that should not interfere with your normal sessions and will only trip bad guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that said:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you set maximum and activate to the maximum value (2.000.000) they will never get triggered, you can then use your alert rate to 'gauge' where your treshold lies (use it in stead of where your 80% watermark would be for max for example).&lt;/P&gt;
&lt;P&gt;you should set the alert rate to where you think it needs to be and then monitor it for a while. if it gets tripped a lot, increase, if it doesn't get tripped, decrease. once you have youyr 'sweet spot' you can decide to move on and set your activate and max (you'll probably want to leave your alert at that level, so you know something is up if it gets tripped, then add max at about 10-25% more connections/sec and your activate depending on your choice of RED or cookies (RED at the same rate as alert, cookies at 0 preferably or 60-70% of alert if you don'tlike cookies)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this makes sense &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 10:04:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199260#M59070</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-07T10:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection  - alert only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199324#M59083</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;good info as always reaper. But if I do set the maximum and activate rates to 2,000,000 where do I look to see the "alert" rates sinces they will not be listed as an alert&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 13:26:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199324#M59083</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-07T13:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection  - alert only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199327#M59084</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is one location on zone protetion that done not have an alert setting and that is what caused my VPN to break, I am including a pick of those setting&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noalert.PNG" style="width: 789px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13693i38AA1F7FBEB8A613/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="noalert.PNG" alt="noalert.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 13:50:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199327#M59084</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-07T13:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection  - alert only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199329#M59085</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another section of zone protection with no alert setting&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="noalert.PNG" style="width: 288px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13694iA2344BF01FC71BB8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="noalert.PNG" alt="noalert.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 13:51:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199329#M59085</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-07T13:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection  - alert only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199330#M59086</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I need to retract that last one it does have an alert setting &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; my bad LOL&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 13:54:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199330#M59086</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-07T13:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection  - alert only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199333#M59088</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The alerts will be included within your 'Threat' logs on the firewall, specifically (subtype eq flood). These will be seen with the action as 'allow' and the severity as 'critical' if it's hitting the 'alert' value.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as the IP Option Drop settings there wouldn't really be an 'alert' option for this, it's either something you want to allow or not. You can find more detailed information about what all the options are actually looking for &lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/network/network-network-profiles-zone-protection/packet-based-attack-protection/ip-drop" target="_blank"&gt;HERE&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 14:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199333#M59088</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-07T14:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Zone protection  - alert only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199334#M59089</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I guess&amp;nbsp; I do have the option to turn the IP option drop settings. My goal is to utillize as many features of the PA as I can to get the mose bang for my buck so to speak LOL&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 14:30:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-alert-only/m-p/199334#M59089</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-07T14:30:09Z</dc:date>
    </item>
  </channel>
</rss>

