<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Aggregate vs Zone protection profiles in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-vs-zone-protection-profiles/m-p/361952#M88249</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; I understand it can be different for classified depending server/application itself, but am I right in my understanding of aggregate vs zone protection profiles.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Nov 2020 18:41:15 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2020-11-10T18:41:15Z</dc:date>
    <item>
      <title>Aggregate vs Zone protection profiles</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-vs-zone-protection-profiles/m-p/361663#M88211</link>
      <description>&lt;P&gt;We have separate zone protection profiles for each zone. And the definition of aggregate says that "all &lt;SPAN&gt;thresholds apply to the entire group of devices specified in a DoS Protection policy rule". So if we are trying to protect servers in DMZ, unless we use smaller groups (for which our environment doesn't seem to have a usecase). Do we even need to use Aggregate DOS protection. Only using Classified seems more appropriate in this scenario,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also as i understand, I should be able club multiple DMZ servers in same DOS policy and the thresholds will apply to each server individually.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 16:55:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-vs-zone-protection-profiles/m-p/361663#M88211</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-11-09T16:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate vs Zone protection profiles</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-vs-zone-protection-profiles/m-p/361782#M88224</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Also as i understand, I should be able club multiple DMZ servers in same DOS policy and the thresholds will apply to each server individually.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you have everything setup under just classified profile then yes that's correct.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So not knowing anything about your environment I can't tell you if you should use aggregate, but I&amp;nbsp;&lt;EM&gt;can&amp;nbsp;&lt;/EM&gt;tell you that in the vast majority of environments you wouldn't throw all of your public services in the same DoS entry. If you're properly tuning your DoS profiles you shouldn't have the exact same values for your&amp;nbsp;&lt;EM&gt;x&amp;nbsp;&lt;/EM&gt;website as you would have for&amp;nbsp;&lt;EM&gt;y&amp;nbsp;&lt;/EM&gt;website or your Exchange server for instance. It's pretty rare I come across an environment where grouping them all under a sole entry is advisable.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 02:45:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-vs-zone-protection-profiles/m-p/361782#M88224</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-11-10T02:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate vs Zone protection profiles</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-vs-zone-protection-profiles/m-p/361952#M88249</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; I understand it can be different for classified depending server/application itself, but am I right in my understanding of aggregate vs zone protection profiles.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 18:41:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-vs-zone-protection-profiles/m-p/361952#M88249</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-11-10T18:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Aggregate vs Zone protection profiles</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggregate-vs-zone-protection-profiles/m-p/361953#M88250</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So your understanding is that you&amp;nbsp;&lt;EM&gt;shouldn't&amp;nbsp;&lt;/EM&gt;set an aggregate profile because you already have Zone Protection configured on the zone right? The zone protection can accomplish the same thing as an aggregate profile, but you would generally have your Zone Protection values set much higher than you ever would on a DoS profile. If you're just going to set those values high enough that your ZP would trip anyways then yes you wouldn't setup an aggregate profile.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 18:56:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggregate-vs-zone-protection-profiles/m-p/361953#M88250</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-11-10T18:56:55Z</dc:date>
    </item>
  </channel>
</rss>

