<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question on getting started with Reconnaissance Protection thresholds in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-getting-started-with-reconnaissance-protection/m-p/330602#M83802</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138646"&gt;@BSwientoniowski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/89891"&gt;@shawnhafen&lt;/a&gt;&amp;nbsp;mentioned and you've pointed out in your question, the problem with giving any sort of general criteria on how to calculate these thresholds is that they will&amp;nbsp;&lt;EM&gt;always&amp;nbsp;&lt;/EM&gt;be different.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outside of continually monitoring these values and reviewing logs over a period of time to generate a rough idea of what you should start at, it's always going to be little bit of trial and error involved here to make them effective.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2020 17:57:32 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-05-29T17:57:32Z</dc:date>
    <item>
      <title>Question on getting started with Reconnaissance Protection thresholds</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-getting-started-with-reconnaissance-protection/m-p/330518#M83779</link>
      <description>&lt;P&gt;I know the question about how to set Reconnaissance Protection thresholds has been asked dozens of times.&amp;nbsp; The answer is always "it depends on your environment and situation".&amp;nbsp; I understand that there can't be a one-size fits all best practice. It seems as though a trial-and-error approach is how you should dial in the thresholds and intervals.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;But are there any unique factors that should be taken into consideration that could give you a general idea rather than taking shots in the dark?&amp;nbsp; Like how many different hosts and services are accessible from that zone?&amp;nbsp; Average connections per second? Frequency of any types of events in the threat logs?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 13:52:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-getting-started-with-reconnaissance-protection/m-p/330518#M83779</guid>
      <dc:creator>BSwientoniowski</dc:creator>
      <dc:date>2020-05-29T13:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Question on getting started with Reconnaissance Protection thresholds</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-getting-started-with-reconnaissance-protection/m-p/330561#M83789</link>
      <description>&lt;P&gt;A while back I went down this same path, it is a very loose control and does require a lot of attention because something like a shopping season, COVID stimulus checks, or other events may cause spikes in traffic that you dont want to drop.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are some places to look for evaluating your CPS over time:&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/zepryspet/GoPAN" target="_blank"&gt;https://github.com/zepryspet/GoPAN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-cps-measurements-for-setting-flood-thresholds/how-to-measure-cps.html#id2f43d329-3860-4689-a2e4-b7d19ded7966" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-cps-measurements-for-setting-flood-thresholds/how-to-measure-cps.html#id2f43d329-3860-4689-a2e4-b7d19ded7966&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 16:48:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-getting-started-with-reconnaissance-protection/m-p/330561#M83789</guid>
      <dc:creator>shawnhafen</dc:creator>
      <dc:date>2020-05-29T16:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Question on getting started with Reconnaissance Protection thresholds</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-getting-started-with-reconnaissance-protection/m-p/330602#M83802</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138646"&gt;@BSwientoniowski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/89891"&gt;@shawnhafen&lt;/a&gt;&amp;nbsp;mentioned and you've pointed out in your question, the problem with giving any sort of general criteria on how to calculate these thresholds is that they will&amp;nbsp;&lt;EM&gt;always&amp;nbsp;&lt;/EM&gt;be different.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outside of continually monitoring these values and reviewing logs over a period of time to generate a rough idea of what you should start at, it's always going to be little bit of trial and error involved here to make them effective.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 17:57:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-getting-started-with-reconnaissance-protection/m-p/330602#M83802</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-05-29T17:57:32Z</dc:date>
    </item>
  </channel>
</rss>

