- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
on 11-12-2019 02:04 PM - edited on 07-08-2020 02:17 PM by DawgsFan
Packet buffer protection defends the firewall from single session denial-of-service DoS attacks. The Enable Packet Buffer Protection best practice check ensures packet buffer protection is enabled on each zone.
A single session on a firewall can consume packet buffers at a high volume. These attacks flood the target to consume all of the target's available resources until the target becomes unavailable. However, if zone protection on the packet buffer is enabled, the firewall will monitor high buffer utilization and take action if an abusive session is detected.
For more information on how to Enable Packet Buffer Protection, please review the following article:
Packet Buffer Protection (TechDocs - PAN-OS® Administrator’s Guide)