04-22-2021 11:12 AM
For TCP flood logs should only show "random-drop" with RED configured.
"drop" for TCP flood is this coming from options set under "TCP Drop" options under Packet Based Attack Protection.
04-22-2021 11:43 AM
Good Day.
Flood Protection is typically only used for the TCP/UDP/IP/IPv6 protections under the first tab in the Zone Protection Profile.
It is recommended to do SynCookies vs RED for traffic from External zone.
Thank you.
04-22-2021 02:27 PM
@SteveCantwell These are my flood protection settings. I should be seeing only random-drop in logs. What is causing the 'drop' logs?
04-22-2021 03:09 PM - edited 04-22-2021 03:22 PM
That is a good question... I have my FW configured for Syn Cookies per PANW. RED is typically only for UDP traffic, not TCP... so perhaps there is some internal logic at play here. Best to swap it (correctly... ) to SYN Cookies. This is per PANW recommendations.
Oh, I also think.. that proper 3 way TCP handshake will be random dropped, but if some src IP did not respond and sent a 2nd SYN packet, the FW will probably DROP that... that is what I think is happening...
Anything else I can assist with?
04-22-2021 03:40 PM
@SteveCantwell Thanks for your effort to answer this. I will probably ask support to have a good clarification.
And regarding your SYN-Cookie suggestion, I had it enabled recently but reverted back to RED when we found during an internal scan, that because firewall is replying SYN's on servers behalf it was also giving SYN replies when the servers did not even exist. We would not like to have that when we have /24 range facing internet.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!