<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High amount of traffic to exchange server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/high-amount-of-traffic-to-exchange-server/m-p/394919#M91204</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might want to look into Zone protection / Dos protection :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/zone-protection-and-dos-protection.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/zone-protection-and-dos-protection.html&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/9-1/dos-and-zone-protection-best-practices.html" target="_self"&gt;dos-and-zone-protection-best-practices&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Mar 2021 11:59:37 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2021-03-30T11:59:37Z</dc:date>
    <item>
      <title>High amount of traffic to exchange server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/high-amount-of-traffic-to-exchange-server/m-p/394850#M91196</link>
      <description>&lt;P&gt;We are seeing a high amount of traffic coming from outside public IPs to our exchange server. It's more than 2GB and sometimes more than 4GB of traffic. Initially, we blocked these IPs in firewall policy but every time after blocking the IPs, some more new public IPs keep coming with high traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are suspecting maybe it's some kind of attack because we don't see this high amount of traffic before. Need to investigate this to block the traffic if it's a kind of attack.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any option to configure alerts to receive if anyone IPs utilizing more than 100MB of traffic?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 06:22:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/high-amount-of-traffic-to-exchange-server/m-p/394850#M91196</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2021-03-30T06:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: High amount of traffic to exchange server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/high-amount-of-traffic-to-exchange-server/m-p/394918#M91203</link>
      <description>&lt;P&gt;Have you tried to use DDOS policy that only alerts ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/zone-protection-and-dos-protection/dos-protection-against-flooding-of-new-sessions/end-a-single-session-dos-attack.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/zone-protection-and-dos-protection/dos-protection-against-flooding-of-new-sessions/end-a-single-session-dos-attack.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if needed enable addtional treat logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/pan-os-8-1-2-introduces-new-log-options/ba-p/217858" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/blogs/pan-os-8-1-2-introduces-new-log-options/ba-p/217858&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it is layer 7 ddos you may need to do SSL inbound Decription and make custom signature about how to block the traffic based on common things in the HTTP requests of the attackers. This may help:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/automation-api-discussions/version-10-no-7-byte-limit-for-sinatures-examples-for-layer-7-l7/td-p/394734" target="_blank"&gt;https://live.paloaltonetworks.com/t5/automation-api-discussions/version-10-no-7-byte-limit-for-sinatures-examples-for-layer-7-l7/td-p/394734&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 12:00:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/high-amount-of-traffic-to-exchange-server/m-p/394918#M91203</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-30T12:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: High amount of traffic to exchange server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/high-amount-of-traffic-to-exchange-server/m-p/394919#M91204</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might want to look into Zone protection / Dos protection :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/zone-protection-and-dos-protection.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/zone-protection-and-dos-protection.html&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/9-1/dos-and-zone-protection-best-practices.html" target="_self"&gt;dos-and-zone-protection-best-practices&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 11:59:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/high-amount-of-traffic-to-exchange-server/m-p/394919#M91204</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-03-30T11:59:37Z</dc:date>
    </item>
  </channel>
</rss>

