Statics for DoS Protection

L4 Transporter

Statics for DoS Protection

Since DoS protection is for more granular protection of a server, how can i see the statics for the particular server i want to protect.  Wouldn't we need to know the pps statics and sessions for that particular server.

 

L4 Transporter

Re: Statics for DoS Protection

Someone created a script that will give you a baseline of your CPS that you can use to build out or fine tune your protection profiles:

 

https://www.reddit.com/r/paloaltonetworks/comments/9a26yq/how_to_get_a_baseline_for_floodzone_protec...

 

Word of caution, you should sample a large enough timeframe to include "normal" peak high traffic times, if you tune the CPS too low and then run into a Christmas shopping traffic spree or whatever else might spike yoyur traffic up you will start dropping incoming traffic/sessions. 

 

p.s. This is not my tool, I have tried it, it does what it claims to do but in the end the tuning you do needs to be well thought out and probably take into consideration data collected over a range of times then adjusted for a margin of error. 

L4 Transporter

Re: Statics for DoS Protection

@hshawn Thanks, I will give it a try. Since this is a third party script. Does not PA itself provide a method to make up for this baseline. It doesn't make sense to give the feature and not tell how to calculate values to be used for this feature. Most of the commands mentioned in the knowledgebase documents are for global use only.

L4 Transporter

Re: Statics for DoS Protection

Nothing specific that I am aware of although they do have some "secret" tools for internal use and if you ask nicely your SE might run some of them for you but to be honest I have no idea if this function would be one of them

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!