Type of block action: whether the hardware
(hw) or software (sw) blocked the IP address. When you configure
a DoS Protection policy or a Security policy that uses a Vulnerability
Protection profile to block connections from source IPv4 addresses,
the firewall automatically blocks that traffic in hardware before
those packets use CPU or packet buffer resources. If attack traffic
exceeds the blocking capacity of the hardware, the firewall uses
software to block the traffic. |