<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone Protection CPS Calculations - Make ZERO sense in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/414626#M93155</link>
    <description>&lt;P&gt;John,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;send me a PM (and confirm your account is set up for PMs) and I will send you a zoom link&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jun 2021 22:15:32 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2021-06-22T22:15:32Z</dc:date>
    <item>
      <title>Zone Protection CPS Calculations - Make ZERO sense</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/413701#M93005</link>
      <description>&lt;P&gt;I have been collecting CPS (total, TCP, UDP, IP) via OIDs using PRTG for ~6 weeks.&amp;nbsp; I have all the data I need (I think).&amp;nbsp; However, the &lt;A title="DoS Zone Protection best practice documentation" href="https://docs.paloaltonetworks.com/best-practices/9-1/dos-and-zone-protection-best-practices/dos-and-zone-protection-best-practices/deploy-dos-and-zone-protection-using-best-practices.html" target="_self"&gt;DoS Zone Protection best practice documentation&lt;/A&gt; leaves a LOT to be desired as it's not clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone has tried to setup zone protection (SYN, UDP, IP, etc.) flood protection, and understand HOW to actually calculate the proper CPS for:&amp;nbsp; Alarm, Activate, Maximum settings please explain the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Alarm Rate&amp;nbsp;&lt;SPAN&gt;—Set 15-20% above the average zone CPS rate to accommodate normal fluctuations.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;* This I believe I have, as I used the total CPS + 20% higher&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;Activate&amp;nbsp;&lt;SPAN&gt;—Set just above the zone’s peak CPS rate to begin dropping connections to mitigate floods.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;* What does this even mean??&amp;nbsp; What is "just above" the zones peak CPS rate?&amp;nbsp; Peak rate per day?&amp;nbsp; Per hour?&amp;nbsp; Per decade? Per what??&amp;nbsp; Makes zero sense.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class="p"&gt;&lt;UL&gt;&lt;LI&gt;Maximum&amp;nbsp;&lt;SPAN&gt;—Set to 80-90% of firewall capacity. Account for other resource-consuming features. Crossing this threshold blocks new connections until the CPS rate falls below the threshold.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class="lia-indent-padding-left-60px"&gt;&lt;SPAN&gt;* How do we figure out the FW capacity??&amp;nbsp; PA5280 - what is the Maximum FW capacity of what?&amp;nbsp; CPS?&amp;nbsp; The only settings for each FW are:&amp;nbsp; Maximum Sessions, and New Connections per second&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;Also - the activate MUST be different for UDP, IP, ICMP, etc.&amp;nbsp; How are THOSE configured?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I hope someone has done this successfully and can share their wisdom, as the documentation and TAC isn't very helpful.&amp;nbsp; They just provide the links to the documents about best practices, etc.&amp;nbsp; Not helpful.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thank you.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Jun 2021 21:06:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/413701#M93005</guid>
      <dc:creator>johnlinkowsky</dc:creator>
      <dc:date>2021-06-16T21:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection CPS Calculations - Make ZERO sense</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/413860#M93016</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let's take a look at this screen capture&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_0-1623939674135.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34473i37F67493F1D39682/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SteveCantwell_0-1623939674135.png" alt="SteveCantwell_0-1623939674135.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You stated that you have been collecting information.&amp;nbsp; Great.&amp;nbsp; What is the lowest CPS, what is average, and what is the highest CPS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are able to answer these questions, then you should be able to determine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HOW MANY CONNECTIONS DO&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;YOU&lt;/STRONG&gt; WANT TO HAVE INBOUND TO YOUR FW?.&amp;nbsp; &amp;nbsp; And when do you want to limit if that number increases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You asked about the Activate number.&amp;nbsp; How many CPS (not per day, per week, month.. but per second).... how many connection per second do you want being allowed by the FW.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for UDP traffic.&amp;nbsp; Do you have much coming inbound from the Internet?&amp;nbsp; Is this the area you need to focus on?&lt;/P&gt;
&lt;P&gt;Or will it be TCP/IP, in which Syn Cookies is what you want.&amp;nbsp; A client MUST provide a 3 way handshake to make a connection. So do you want to allow 1000 unanswered SYNs (known as Syn Floods) before you start to drop/restrict.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My suggestion is that you go into the Beacon training website (beacon.paloaltonetworks.com) and look at PANW 110 module on "block packet attacks" module to assist you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 14:29:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/413860#M93016</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-06-17T14:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection CPS Calculations - Make ZERO sense</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/414360#M93108</link>
      <description>&lt;P&gt;Thank you for the reply &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;.&amp;nbsp; However, many of these questions cannot be answered.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How many connections do I want inbound?&amp;nbsp; - As many as needed that are legitimate.&amp;nbsp; There is no way to answer this, as traffic increases/decreases all the time.&lt;/LI&gt;&lt;LI&gt;How many CPS do I want being allowed by the FW?&amp;nbsp; - Again, as many as needed as long as they are legit.&amp;nbsp; There is no 'set' number.&lt;/LI&gt;&lt;LI&gt;UDP traffic - is this an area that need to be focused on?&amp;nbsp; - what does that mean?&amp;nbsp; We don't want UDP flooding inbound to our FW.&lt;/LI&gt;&lt;LI&gt;I agree with the 3 way handshake.&amp;nbsp; I'm not sure a 'good number' to allow before we start to drop it.&amp;nbsp; How do we know what a 'good number' would be to set this with?&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I will check out the Beacon module, as soon as my access to that site is fixed.&amp;nbsp; Currently have a ticket open.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John L.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 19:47:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/414360#M93108</guid>
      <dc:creator>johnlinkowsky</dc:creator>
      <dc:date>2021-06-21T19:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection CPS Calculations - Make ZERO sense</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/414370#M93110</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/158151"&gt;@johnlinkowsky&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want, I am available for a zoom session.&amp;nbsp; Just&amp;nbsp; tell me when you want to chat and I will send you a Zoom link to discuss this.&amp;nbsp; I am available after 3pm CST on a daily basis.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 20:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/414370#M93110</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-06-21T20:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection CPS Calculations - Make ZERO sense</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/414599#M93151</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;- much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm available tomorrow (6/23) at 4:30PM ET (3:30pm CT) if that works for you.&amp;nbsp; I've been hounding my PA team about this, and they have not been able to find anyone who can explain this to me.&amp;nbsp; They have admitted that they have poor resources on this topic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll take any help I can get.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John L.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 20:25:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/414599#M93151</guid>
      <dc:creator>johnlinkowsky</dc:creator>
      <dc:date>2021-06-22T20:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Protection CPS Calculations - Make ZERO sense</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/414626#M93155</link>
      <description>&lt;P&gt;John,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;send me a PM (and confirm your account is set up for PMs) and I will send you a zoom link&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 22:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-protection-cps-calculations-make-zero-sense/m-p/414626#M93155</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-06-22T22:15:32Z</dc:date>
    </item>
  </channel>
</rss>

