What’s the best way to protect against DoS attacks that
try to take down your network? Layers at the perimeter, at zone borders,
and for critical devices!
A Denial-of-Service (DoS) attack attempts to make
a network device or resource unavailable to legitimate users by
disrupting services. These attacks usually come from the internet
but can come from misconfigured or compromised internal devices.
The typical method is to flood the target with resource requests
until the requests consume all of the target’s available resources—memory,
CPU cycles, and bandwidth—and the target becomes unavailable. Typical
targets are internet-facing devices users can access from outside the
corporate network, such as web servers and database servers. As
part of a layered approach to DoS protection, Palo Alto Networks firewalls
provide three DoS attack mitigation tools.