Baseline Procedure for DOS Prevention

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Baseline Procedure for DOS Prevention

L3 Networker

Hello everyone,

I was looking at setting up the DOS profile/protections on a PA-3020.  I obviously need to baseline the traffic/system and was curious if there are

any docs, Perhaps hidden, that would help me in this.

Essentially I will need to grab stats.  I realize Cacti can do this, but my customer does not have any available tools. : (

thank you in advance,

Don

2 accepted solutions

Accepted Solutions

L7 Applicator

You have probably seen the two main documents here.

Understanding DoS Protection

Understanding DoS Logs and Counters

Without actual data gathered before hand, I would start by turning on features that can be done so in alert mode and monitoring the logs every few days.  Once the appropriate levels are obvious then converting to drop.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

View solution in original post

Thank you very much..

 

There's no shortcut : )

 

Don

View solution in original post

2 REPLIES 2

L7 Applicator

You have probably seen the two main documents here.

Understanding DoS Protection

Understanding DoS Logs and Counters

Without actual data gathered before hand, I would start by turning on features that can be done so in alert mode and monitoring the logs every few days.  Once the appropriate levels are obvious then converting to drop.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Thank you very much..

 

There's no shortcut : )

 

Don

  • 2 accepted solutions
  • 3312 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!