Classified DoS Protection profiles set thresholds
that apply to each individual device specified in the DoS Protection
rule to protect individual or small groups of critical servers.
For example, an Alarm Rate threshold of 10,000 CPS means that when
the total new CPS to any individual server specified in the rule
exceeds 10,000 CPS, the firewall triggers an alarm message. Select
this option and specify the following: Profile—Select
a Classified DoS Protection profile to apply to this rule. Address—Select whether incoming connections
count toward the thresholds in the profile if they match the source-ip-only, destination-ip-only,
or src-dest-ip-both.
The firewall
consumes more resources to track src-dest-ip-both counters
than to track only the source IP or only the destination IP counters.
If
you specify a Classified DoS Protection profile, only the incoming connections
that match a source IP address, destination IP address, or source and
destination IP address pair count toward the thresholds specified
in the profile. For example, you can specify a Classified DoS Protection
profile with a Max Rate of 100 cps, and specify
an Address setting of source-ip-only in
the rule. The result would be a limit of 100 connections per second
for that particular source IP address.
Don’t
use source-ip-only or src-dest-ip-both for
internet-facing zones because the firewall can’t store counters
for all possible internet IP addresses. Use destination-ip-only in
perimeter zones. Use destination-ip-only to
protect individual critical devices. Use source-ip-only and
the Alarm threshold to monitor suspect hosts
in non-internet-facing zones.
|