<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DOS profile for critical servers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dos-profile-for-critical-servers/m-p/343043#M85909</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107710"&gt;@OwenFuller&lt;/a&gt;&amp;nbsp; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&amp;nbsp;when I tried to answer on my RFC1918 post, I am not able to do that. It is giving me Error. Thanks Owen and BPry, yes, we are using Public IP addresses and it is just my manager want to implement to have better security to block private IP block from public zone.&lt;BR /&gt;&lt;BR /&gt;Also, can you please look into my DOS profile rule question. Thanks for the help and support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Aug 2020 14:54:02 GMT</pubDate>
    <dc:creator>shafi021</dc:creator>
    <dc:date>2020-08-10T14:54:02Z</dc:date>
    <item>
      <title>DOS profile for critical servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dos-profile-for-critical-servers/m-p/343037#M85908</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to create the DOS profile for critical servers. I read that I can use classified type so connection count toward only one IP address.&lt;BR /&gt;&lt;BR /&gt;My question is can I add multiple servers IPs in same DOS Rule or I need to create multiple DOS rules. Also, I might need to tune threshold base on servers so is it better to create new DOS rule?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If I use same DOS rule then connection count will still be per destination IP or will it act like aggregate to all the Destination IPs ?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 14:49:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dos-profile-for-critical-servers/m-p/343037#M85908</guid>
      <dc:creator>shafi021</dc:creator>
      <dc:date>2020-08-10T14:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: DOS profile for critical servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dos-profile-for-critical-servers/m-p/343043#M85909</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107710"&gt;@OwenFuller&lt;/a&gt;&amp;nbsp; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&amp;nbsp;when I tried to answer on my RFC1918 post, I am not able to do that. It is giving me Error. Thanks Owen and BPry, yes, we are using Public IP addresses and it is just my manager want to implement to have better security to block private IP block from public zone.&lt;BR /&gt;&lt;BR /&gt;Also, can you please look into my DOS profile rule question. Thanks for the help and support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 14:54:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dos-profile-for-critical-servers/m-p/343043#M85909</guid>
      <dc:creator>shafi021</dc:creator>
      <dc:date>2020-08-10T14:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: DOS profile for critical servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dos-profile-for-critical-servers/m-p/343049#M85911</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139406"&gt;@shafi021&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My question is can I add multiple servers IPs in same DOS Rule or I need to create multiple DOS rules. Also, I might need to tune threshold base on servers so is it better to create new DOS rule?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;You can add multiple IPs to the same DoS rulebase entry, but keep in mind that you can only have one aggregate and one classified profile assigned to the entry. So if you have multiple public resources servicing for example DNS services, I would generally only make one entry. That entry would have an aggregate and a classified rulebase entry that has been fined tuned for that service.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;If I use same DOS rule then connection count will still be per destination IP or will it act like aggregate to all the Destination IPs ?&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;So this actually depends on how you setup the entry. An aggregate profile would effect every destination in that rule. Classified can take into account specific destination IPs which would be limited to the destination address instead of aggregated across the entry matched rulebase entry.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;Just in general, I would never configure a DOS Protection rulebase entry to service multiple different services. If you have a public Exchange server I would want to see a separate entry for Exchange, likewise I would create a separate&amp;nbsp;entry&amp;nbsp;&amp;nbsp;for public web resources or VPN appliances.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;You want to have your DoS profiles (aggregate and classified) as specific as you can get them to allow them to actually do their job. You can't really do that if you have the same profile protecting a wide array of services.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;The only caveat that would come into play is on smaller platforms where you have the potential of running into object limits on the DoS profiles. That's the only time where I start recommending people group like services into the same profile. So maybe instead of having a separate profile for each web service we go down to a generic "Public Websites" type of profile; but if your platform is capable of supporting a profile for each public service, there's no reason not to fully utilize that capability.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 15:08:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dos-profile-for-critical-servers/m-p/343049#M85911</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-08-10T15:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: DOS profile for critical servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dos-profile-for-critical-servers/m-p/343105#M85919</link>
      <description>&lt;P&gt;TEST 2&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 19:00:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dos-profile-for-critical-servers/m-p/343105#M85919</guid>
      <dc:creator>kh-rohit</dc:creator>
      <dc:date>2020-08-10T19:00:05Z</dc:date>
    </item>
  </channel>
</rss>

