PA-3320 Session's Setup Alerts for session limits reached

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PA-3320 Session's Setup Alerts for session limits reached

L1 Bithead

Today we had a networking issue that was random and hard to track down.  Turns out to be DDOS attack to our Citrix.  Since the Dashboard on the GUI doesn't show the BIG RED OMG Light when your maxed we missed it for sometime.

PAlmart_0-1610051721540.png

does anyone know how to setup Email alerts for sessions over a certain load.  20%.. 30%... 40%... AND 99%

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

I don't believe there is an explicit alert for session table utilization

accelerated ageing kicks in at 80% by default (device > setup > session > session setting) which may create a log entry in the system log

 

It is highly advisable to set up zone protection profiles (using SYN cookies) and enabling packet buffer protection on your zones

packet buffer protection will start to alert at 50% usage (of the packet buffer)

 

you could additionally set up a DoS protection rule that limits the total number of allowed concurrent sessions towards your citrix farm, to prevent a DDoS attack from flooding your entire firewall

 

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

I don't believe there is an explicit alert for session table utilization

accelerated ageing kicks in at 80% by default (device > setup > session > session setting) which may create a log entry in the system log

 

It is highly advisable to set up zone protection profiles (using SYN cookies) and enabling packet buffer protection on your zones

packet buffer protection will start to alert at 50% usage (of the packet buffer)

 

you could additionally set up a DoS protection rule that limits the total number of allowed concurrent sessions towards your citrix farm, to prevent a DDoS attack from flooding your entire firewall

 

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 2135 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!