random-drop vs drop - zone protection

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

random-drop vs drop - zone protection

L4 Transporter

For TCP flood logs should only show "random-drop" with RED configured.

"drop" for TCP flood is this coming from options set under "TCP Drop" options under Packet Based Attack Protection. 

 

image.png

 

 

9 REPLIES 9

Cyber Elite
Cyber Elite

Good Day.

 

Flood Protection is typically only used for the TCP/UDP/IP/IPv6 protections under the first tab in the Zone Protection Profile.

It is recommended to do SynCookies vs RED for traffic from External zone.

 

Thank you.

Help the community: Like helpful comments and mark solutions

@SteveCantwell  These are my flood protection settings. I should be seeing only random-drop in logs. What is causing the 'drop' logs?

image.png

That is a good question... I have my FW configured for Syn Cookies per PANW.  RED is typically only for UDP traffic, not TCP... so perhaps there is some internal logic at play here.  Best to swap it (correctly... ) to SYN Cookies.  This is per PANW recommendations.

 

Oh, I also think.. that proper 3 way TCP handshake will be random dropped, but if some src IP did not respond and sent a 2nd SYN packet, the FW will probably DROP that... that is what I think is happening...

 

Anything else I can assist with?

Help the community: Like helpful comments and mark solutions

@SteveCantwell Thanks for your effort to answer this. I will probably ask support to have a good clarification.

 

And regarding your SYN-Cookie suggestion, I had it enabled recently but reverted back to RED when we found during an internal scan, that because firewall is replying SYN's on servers behalf it was also giving SYN replies when the servers did not even exist. We would not like to have that when we have /24 range facing internet.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!