Is it possible to limit concurrent session per Zone or per source IP?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Is it possible to limit concurrent session per Zone or per source IP?

L2 Linker

Hi Guys.

I was looking to limit session per Zone or per src IP and I found this discussion, so we are in version 4.1.8 and cannot find any option on the QoS to do this limit ?

Thanks for your help

1 accepted solution

Accepted Solutions

L4 Transporter

Hi,

It is not under the QoS setting.

To do this, you need to go to the policy tab and configure the DoS policy. You need to input the source and destination zones you want to apply the control, and choose

- protect instead of allow/any as the action

- classified instead of aggregated as the type of protection

- choose whether you want to consider a counter hit by just the src IP, src IP + Dst IP or just the dst IP

- create the DoS profile, and under the resource protection input the limit

Regards,

Jones

View solution in original post

3 REPLIES 3

L4 Transporter

Hi,

It is not under the QoS setting.

To do this, you need to go to the policy tab and configure the DoS policy. You need to input the source and destination zones you want to apply the control, and choose

- protect instead of allow/any as the action

- classified instead of aggregated as the type of protection

- choose whether you want to consider a counter hit by just the src IP, src IP + Dst IP or just the dst IP

- create the DoS profile, and under the resource protection input the limit

Regards,

Jones

Hi,

Thanks for your quick answer.

This is greate.

Regards

Hi,
I have just a small question about the DoS profile, for a test I configured the profile with the value below for Syn flood:

Alarm Rate (packets/sec) 50
Activate Rate (packets/sec) 50
Maximal Rate (packets/sec) 800
Block Duration (seconds) 300


After flooding with 100pps I can see on the threat log that syn flood was detected and randomly was dropped, but how about the first value (Alarm Rate) where I should receive the Alarm ? as above I should receive an alarm after 50pps ?

Thanks for your help

Regards

  • 1 accepted solution
  • 3907 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!