incomplete and ddos drops

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

incomplete and ddos drops

L4 Transporter

Hi

The following report shows incomplete

Database: Traffic Log
Columns: Source Zone, Source Address, Source Port, Destination Zone, Destination Address, Destination Port,
Application, Bytes
Query Builder: (app eq incomplete) and (port.dst leq 1023)

but the " show counter global filter category flow aspect dos "
does not give any indication of drops

 

name value rate severity category aspect description    
flow_dos_red_tcp 1143291 0 drop flow dos Packets dropped: Zone protection protocol 'tcp-syn' RED
flow_dos_pf_ipfrag 60010 0 drop flow dos Packets dropped: Zone protection option 'discard-ip-frag'
flow_dos_pf_icmplpkt 1100 0 drop flow dos Packets dropped: Zone protection option 'discard-icmp-large-packet'
flow_dos_pf_tcpoverlappingmismatch 21198 0 drop flow dos Packets dropped: Zone protection option 'discard-overlapping-tcp-segment-mismatch'
flow_dos_zone_red_max 446965 0 drop flow dos Packets dropped: Maximal zone RED threshold reached
flow_dos_zone_red_act 696326 0 drop flow dos Packets dropped: Activate zone RED threshold reached, random early drop
flow_dos_rule_drop 412022 0 drop flow dos Packets dropped: Rate limited or IP blocked
flow_dos_rule_drop_classified 412022 0 drop flow dos Packets dropped: due to classified rate limiting
                 

 


So how can i co-relate ?

Thanks

 

1 REPLY 1

Cyber Elite
Cyber Elite

Incomplete does not mean that your firewall dropped it.

For example if you try to connect to website and this website is down then client PC in your network will send SYN packet.

As website is down then no SYN-ACK will follow and TCP 3-way handshake is incomplete.

That will be logged as application.

 

If you open session then most likely you see "1 packet sent, 0 packet received"

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 1646 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!