Triggering of Packet based protection under Zone protection profile

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Triggering of Packet based protection under Zone protection profile

L0 Member

In the PA documentation, it says Zone protection is applicable to new connections that does not have any existing session. To mitigate flood protection that will works definitely.  However under Zone protection profile we have packet based attack protection which deals packet based attacks  which uses certain option in layer3 and 4 of a packet. 
malfunction / corrupted Packets  that  may intended for attack may arrive during middle of connection which may match to the existing session, for example initial packet of a new connection may arrive correctly and after few packets attacker may uses those options in the layer3 and layer 4 of packet to do some attacks. So in such cases how PA FW mitigates the such packet based attacks ? Because zone protection profile is applicable to new connections, but in this scenario packet matching to an existing session is bad packet intended for attack.  Documentation clearly  says connection matching to existing session bypasses the Zone protection and DOS protections. 
I have put a prompt in Chatgpt and Gemini they replied that packet based attack protections applies even for the existing session also. Please help to understand this 

0 REPLIES 0
  • 56 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!