<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Idenfiy number of connection of per zone with or without snmp in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/idenfiy-number-of-connection-of-per-zone-with-or-without-snmp/m-p/202536#M59747</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78551"&gt;@RamBalaji&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't really know of a&amp;nbsp;&lt;EM&gt;good&lt;/EM&gt; way to actually do this at all. What I usually recommend is that you set the 'Activate' and 'Maximum' values to something that you&amp;nbsp;&lt;STRONG&gt;know&lt;/STRONG&gt; you aren't going to hit; even if that's your platforms max session rate. Then you play around with the 'Alarm' rate until you essentially baseline the traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then make sure that your 'Action' for your Reconnaissance Protection is 'alert', and you can do the same here and play around with any source exclusions that you need to make.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet Based Attack Protection is something that you'll need to read up on and probably enable outside of business hours to ensure you don't cause any issues. All of these are detailed and you can make the determination on whether or not you want it on, but this is usually where people run into issues with legit traffic getting dropped when they first enable ZP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps a bit.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2018 14:09:18 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-02-27T14:09:18Z</dc:date>
    <item>
      <title>Idenfiy number of connection of per zone with or without snmp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/idenfiy-number-of-connection-of-per-zone-with-or-without-snmp/m-p/202522#M59745</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I need to configure zone protection, how to find the number of connetion per second for each zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried with "show session info" and i can see "new connection establish rate" but i need to take the average for 2 or 3 weeks.&lt;/P&gt;&lt;P&gt;So if its on the snmp which ouid i have to use to monitor or any other method to identify the connection per second on each zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with regards,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 13:51:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/idenfiy-number-of-connection-of-per-zone-with-or-without-snmp/m-p/202522#M59745</guid>
      <dc:creator>RamBalaji</dc:creator>
      <dc:date>2018-02-27T13:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Idenfiy number of connection of per zone with or without snmp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/idenfiy-number-of-connection-of-per-zone-with-or-without-snmp/m-p/202536#M59747</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78551"&gt;@RamBalaji&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't really know of a&amp;nbsp;&lt;EM&gt;good&lt;/EM&gt; way to actually do this at all. What I usually recommend is that you set the 'Activate' and 'Maximum' values to something that you&amp;nbsp;&lt;STRONG&gt;know&lt;/STRONG&gt; you aren't going to hit; even if that's your platforms max session rate. Then you play around with the 'Alarm' rate until you essentially baseline the traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then make sure that your 'Action' for your Reconnaissance Protection is 'alert', and you can do the same here and play around with any source exclusions that you need to make.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet Based Attack Protection is something that you'll need to read up on and probably enable outside of business hours to ensure you don't cause any issues. All of these are detailed and you can make the determination on whether or not you want it on, but this is usually where people run into issues with legit traffic getting dropped when they first enable ZP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps a bit.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 14:09:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/idenfiy-number-of-connection-of-per-zone-with-or-without-snmp/m-p/202536#M59747</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-27T14:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Idenfiy number of connection of per zone with or without snmp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/idenfiy-number-of-connection-of-per-zone-with-or-without-snmp/m-p/202562#M59758</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The way I have done it in the past was take the default vaules. If after a month nothing got blocked, I would halve the values. Then keep this going until we saw an impact and then ramp it back up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 16:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/idenfiy-number-of-connection-of-per-zone-with-or-without-snmp/m-p/202562#M59758</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-27T16:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Idenfiy number of connection of per zone with or without snmp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/idenfiy-number-of-connection-of-per-zone-with-or-without-snmp/m-p/202688#M59771</link>
      <description>&lt;P&gt;Bpry &amp;amp; Otakar.Klier,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for sharing your experience. Environment is critical and needs to applied for 6 location, security team will not allow this approach.&lt;/P&gt;&lt;P&gt;Any other methods available ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with regards,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 05:30:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/idenfiy-number-of-connection-of-per-zone-with-or-without-snmp/m-p/202688#M59771</guid>
      <dc:creator>RamBalaji</dc:creator>
      <dc:date>2018-02-28T05:30:27Z</dc:date>
    </item>
  </channel>
</rss>

