Hi
The following report shows incomplete
Database: Traffic Log Columns: Source Zone, Source Address, Source Port, Destination Zone, Destination Address, Destination Port, Application, Bytes Query Builder: (app eq incomplete) and (port.dst leq 1023)
but the " show counter global filter category flow aspect dos " does not give any indication of drops
name
value
rate
severity
category
aspect
description
flow_dos_red_tcp
1143291
0
drop
flow
dos
Packets
dropped:
Zone protection protocol 'tcp-syn' RED
flow_dos_pf_ipfrag
60010
0
drop
flow
dos
Packets
dropped:
Zone protection option 'discard-ip-frag'
flow_dos_pf_icmplpkt
1100
0
drop
flow
dos
Packets
dropped:
Zone protection option 'discard-icmp-large-packet'
flow_dos_pf_tcpoverlappingmismatch
21198
0
drop
flow
dos
Packets
dropped:
Zone protection option 'discard-overlapping-tcp-segment-mismatch'
flow_dos_zone_red_max
446965
0
drop
flow
dos
Packets
dropped:
Maximal zone RED threshold reached
flow_dos_zone_red_act
696326
0
drop
flow
dos
Packets
dropped:
Activate zone RED threshold reached, random early drop
flow_dos_rule_drop
412022
0
drop
flow
dos
Packets
dropped:
Rate limited or IP blocked
flow_dos_rule_drop_classified
412022
0
drop
flow
dos
Packets
dropped:
due to classified rate limiting
So how can i co-relate ?
Thanks
... View more