- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-29-2016 12:51 AM
Hi,
What are the best practices need to be followed to protect from the ddos dns amplification attack .
How to filter the trace from the log if there is any attack happened ?
Thanks
03-29-2016 06:36 AM
Here's a Tech Note which covers threat & DoD Protection. Check it out: https://live.paloaltonetworks.com/t5/Documentation-Articles/Threat-Prevention-Deployment-Tech-Note/t...
04-03-2016 11:41 PM
Zone protection profile on outside/internet interface will protect your servers from traffic originating from internet.
Zone protection profile on interface where your DNS servers are will prevent your servers sending a lot of traffic towards internet (or some other zone) if they get compromised somehow.
03-29-2016 06:33 AM - edited 03-29-2016 06:33 AM
Zone protection on outside/external/internet interface to protect your servers. And zone protection on the interface where your DNS servers are to prevent your servers being used as amplifiers.
03-29-2016 06:36 AM
Here's a Tech Note which covers threat & DoD Protection. Check it out: https://live.paloaltonetworks.com/t5/Documentation-Articles/Threat-Prevention-Deployment-Tech-Note/t...
04-02-2016 11:53 PM
Hi,
"And zone protection on the interface where your DNS servers are to prevent your servers being used as amplifiers. "
Can you explain how to do that .
Thank you
04-03-2016 11:41 PM
Zone protection profile on outside/internet interface will protect your servers from traffic originating from internet.
Zone protection profile on interface where your DNS servers are will prevent your servers sending a lot of traffic towards internet (or some other zone) if they get compromised somehow.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!