Zone protection profiles disadvantage or drawback

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Zone protection profiles disadvantage or drawback

L0 Member

Hi All

 

Can anyone tell me the Zone protection profiles disadvantage or drawback

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello,

The only thing I can think of is if you change the default settings to be too sensitive. The other thing is if you set this and use the block-ip option, you could cause issues that way. However I always enable it with default settings and watch the threat logs to see what is happening. Then after a few weeks I might lower the default settings, but never more than half. Its actually in the STIG settings to have zone protection on all zones.

 

Regards,

Cyber Elite
Cyber Elite

@MohammedAsikM,

As @OtakarKlier alluded to, there's a lot of advantages and it's something that should be enabled. There's just a few things that you need to think through while enabling it. 

 

I highly recommend using the Alert thresholds to dial in your thresholds before lowing the activate and maximum values for flood protection. Things like the max-concurrent-limit for sessions will require you to do a bit of legwork before changing/enabling the limit, as there is no alert functionality for that. Reconnaissance protection can be dialed in with the alert action before you change the action values. 

  • 1490 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!