- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-06-2026 11:29 PM
In the PA documentation, it says Zone protection is applicable to new connections that does not have any existing session. To mitigate flood protection that will works definitely. However under Zone protection profile we have packet based attack protection which deals packet based attacks which uses certain option in layer3 and 4 of a packet.
malfunction / corrupted Packets that may intended for attack may arrive during middle of connection which may match to the existing session, for example initial packet of a new connection may arrive correctly and after few packets attacker may uses those options in the layer3 and layer 4 of packet to do some attacks. So in such cases how PA FW mitigates the such packet based attacks ? Because zone protection profile is applicable to new connections, but in this scenario packet matching to an existing session is bad packet intended for attack. Documentation clearly says connection matching to existing session bypasses the Zone protection and DOS protections.
I have put a prompt in Chatgpt and Gemini they replied that packet based attack protections applies even for the existing session also. Please help to understand this
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

