12-16-2021 07:30 PM
Hi All
Can anyone tell me the Zone protection profiles disadvantage or drawback
12-17-2021 12:22 PM
Hello,
The only thing I can think of is if you change the default settings to be too sensitive. The other thing is if you set this and use the block-ip option, you could cause issues that way. However I always enable it with default settings and watch the threat logs to see what is happening. Then after a few weeks I might lower the default settings, but never more than half. Its actually in the STIG settings to have zone protection on all zones.
Regards,
12-17-2021 02:26 PM
As @OtakarKlier alluded to, there's a lot of advantages and it's something that should be enabled. There's just a few things that you need to think through while enabling it.
I highly recommend using the Alert thresholds to dial in your thresholds before lowing the activate and maximum values for flood protection. Things like the max-concurrent-limit for sessions will require you to do a bit of legwork before changing/enabling the limit, as there is no alert functionality for that. Reconnaissance protection can be dialed in with the alert action before you change the action values.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!