<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CPS calculation per server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366377#M88697</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If all of your session traffic is logged you can get a&amp;nbsp;&lt;EM&gt;rough&amp;nbsp;&lt;/EM&gt;idea of what your traffic stats are for a given host or just in general. I would recommend just filtering the session info for a given server and scripting an automated pull of the information on a regular basis to form a longer average. Netflow or a PCAP is always going to be the most accurate method of determine traffic stats tough.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep in mind that you can always use the 'alert' value and adjust from there to narrow in on what your activate and maximum values actually need to be.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2020 00:13:46 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-12-01T00:13:46Z</dc:date>
    <item>
      <title>CPS calculation per server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366340#M88690</link>
      <description>&lt;DIV&gt;'Log at Session End,&lt;SPAN&gt;&amp;nbsp;captures the number of connections at the session end."&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I am little confused by this statement. How does 'Log at Session End' help in calculating CPS for a server.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-cps-measurements-for-setting-flood-thresholds/how-to-measure-cps.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-cps-measurements-for-setting-flood-thresholds/how-to-measure-cps.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;And what other method can I specifically use on the firewall for CPS calculation for a specific server.&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 30 Nov 2020 18:01:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366340#M88690</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-11-30T18:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: CPS calculation per server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366377#M88697</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If all of your session traffic is logged you can get a&amp;nbsp;&lt;EM&gt;rough&amp;nbsp;&lt;/EM&gt;idea of what your traffic stats are for a given host or just in general. I would recommend just filtering the session info for a given server and scripting an automated pull of the information on a regular basis to form a longer average. Netflow or a PCAP is always going to be the most accurate method of determine traffic stats tough.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep in mind that you can always use the 'alert' value and adjust from there to narrow in on what your activate and maximum values actually need to be.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 00:13:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366377#M88697</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-12-01T00:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: CPS calculation per server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366403#M88706</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Guys, so this is a question I've had for quite a while. Like what's the best way to get connection per second counts? What should the settings on scan protection be? Why do the firewalls not always identify known scans?&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I've actually worked for Palo Alto for some time and was never able to get good answers to this. Can any one of you help me out, as it's becoming really relevant to me now? Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 04:58:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366403#M88706</guid>
      <dc:creator>Marianaa</dc:creator>
      <dc:date>2020-12-01T04:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: CPS calculation per server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366406#M88708</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks for the information.. . .&amp;nbsp;&lt;A href="https://www.tellpizzahut.online/" target="_self"&gt;tell pizza hut&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 06:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366406#M88708</guid>
      <dc:creator>StevenKnight</dc:creator>
      <dc:date>2020-12-02T06:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: CPS calculation per server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366519#M88715</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; I have setup netflow with PRTG but not sure what I am looking for in here that can give me the numbers to use for in the DoS profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28891iF94AB4FAEFA4B812/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Screenshot from Top Connections&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28890i57F6266AC6DB8BB6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I can script it as well but what do I do with this. Do I count the number of sessions to the server at regular interval for this output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show session all filter destination X.X.X.129&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ID Application State Type Flag Src[Sport]/Zone/Proto (translated IP[Port])&lt;BR /&gt;Vsys Dst[Dport]/Zone (translated IP[Port])&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;1368583 ssl ACTIVE FLOW ND 113.173.225.13[51541]/EXTERNAL/6 (113.173.225.13[51541])&lt;BR /&gt;vsys1 X.X.X.129[443]/DMZN (192.168.8.30[443])&lt;BR /&gt;140406 ssl ACTIVE FLOW ND 209.121.37.106[52465]/EXTERNAL/6 (209.121.37.106[52465])&lt;BR /&gt;vsys1 X.X.X.129[443]/DMZN (192.168.8.30[443])&lt;BR /&gt;1381933 ssl ACTIVE FLOW ND 96.48.142.40[60647]/EXTERNAL/6 (96.48.142.40[60647])&lt;BR /&gt;vsys1 X.X.X.129[443]/DMZN (192.168.8.30[443])&lt;BR /&gt;1594610 ssl ACTIVE FLOW ND 50.98.173.15[61753]/EXTERNAL/6 (50.98.173.15[61753])&lt;BR /&gt;vsys1 X.X.X.129[443]/DMZN (192.168.8.30[443])&lt;BR /&gt;3862404 ssl ACTIVE FLOW ND 50.68.197.84[55053]/EXTERNAL/6 (50.68.197.84[55053])&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 15:18:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366519#M88715</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-12-01T15:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: CPS calculation per server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366826#M88760</link>
      <description>&lt;P&gt;So I found this(&lt;A href="https://github.com/zepryspet/GoPAN" target="_blank"&gt;https://github.com/zepryspet/GoPAN&lt;/A&gt;) to pull zone based CPS stats using snmp and I was also able to map this SNMP in PRTG as well.&lt;/P&gt;&lt;P&gt;But pulling data using GoPan gave more data than PRTG as poll interval is much faster for GoPan. I have to manually sort data though&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still don't get how netflow is usefull, all I see is bandwidth for HTTPS on filtering for the particular server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;or someone else can suggest what i should be doing for sever CPS calculation&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 16:59:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/366826#M88760</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-12-02T16:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: CPS calculation per server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/432977#M95810</link>
      <description>&lt;P&gt;Panorama has a CPS monitor built in- but that monitors CPS for the entire firewall not for the zone in question.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 02:20:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cps-calculation-per-server/m-p/432977#M95810</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2021-09-10T02:20:59Z</dc:date>
    </item>
  </channel>
</rss>

