<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP / UDP Flood in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/298083#M78146</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51438"&gt;@s_quasar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Depends heavily on what type of profile you have configured and what profile they actually hit; Classified will be able to provide you a source-ip because there is a sole address to give you, while Aggregate won't give you a source-ip because it accounts for anything connecting to that protected resource.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Nov 2019 22:13:59 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-11-12T22:13:59Z</dc:date>
    <item>
      <title>TCP / UDP Flood</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/297953#M78130</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have set up a dos rule from outside to my server zone.&lt;/P&gt;&lt;P&gt;Why sometimes I can see attacker and victim IP and sometimes not?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 16:40:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/297953#M78130</guid>
      <dc:creator>s_quasar</dc:creator>
      <dc:date>2019-11-12T16:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: TCP / UDP Flood</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/297992#M78135</link>
      <description>&lt;P&gt;Its is expected:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="exp.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22261iC888F28AA19095D5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="exp.JPG" alt="exp.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="chrome-extension://oemmndcbldboiebfnladdacbdfmadadm/https://knowledgebase.paloaltonetworks.com/servlet/fileField?entityId=ka10g000000D82ZAAS&amp;amp;field=Attachment_1__Body__s" target="_blank"&gt;chrome-extension://oemmndcbldboiebfnladdacbdfmadadm/https://knowledgebase.paloaltonetworks.com/servlet/fileField?entityId=ka10g000000D82ZAAS&amp;amp;field=Attachment_1__Body__s&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 17:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/297992#M78135</guid>
      <dc:creator>myky</dc:creator>
      <dc:date>2019-11-12T17:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: TCP / UDP Flood</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/298083#M78146</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51438"&gt;@s_quasar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Depends heavily on what type of profile you have configured and what profile they actually hit; Classified will be able to provide you a source-ip because there is a sole address to give you, while Aggregate won't give you a source-ip because it accounts for anything connecting to that protected resource.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 22:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/298083#M78146</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-12T22:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: TCP / UDP Flood</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/298088#M78148</link>
      <description>&lt;P&gt;I supposed this. Maybe I can see specific IP attacker and victim because before I activeted a classified rule (now is aggregate).&lt;/P&gt;&lt;P&gt;See the IPs is very useful because I can check in other websites if it is a bad or good IP.&lt;/P&gt;&lt;P&gt;Maybe I can use an aggregate rule as a test and than activete again a classified rule.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 22:21:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/298088#M78148</guid>
      <dc:creator>s_quasar</dc:creator>
      <dc:date>2019-11-12T22:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: TCP / UDP Flood</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/298093#M78151</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51438"&gt;@s_quasar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Remember that you can assign both an aggregate profile and a classified profile in the same DoS entry. If you are just working on building these out now, it might be best to follow this method:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Set Alarm connection rates about where you expect it to be&lt;/LI&gt;&lt;LI&gt;Set Activate Rate to an extremely high value (100,000)&lt;/LI&gt;&lt;LI&gt;Set Max Rate to an extremely high value (100,000)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;You can play around with the alarm rate and watch the logs to see when you actually start getting alerts and start to narrow down what your Activate and Max rates should be under normal traffic loads. The only thing that you won't be able to really analyze like this is the max concurrent session limit, but that should be easily generated from your logs and your session table over a period of time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 22:30:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-udp-flood/m-p/298093#M78151</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-12T22:30:09Z</dc:date>
    </item>
  </channel>
</rss>

