Use DoS protection policy rules and Security policy rules to block single session DoS
        attacks.
    
            
  
    
  
| Where Can I Use This? | What Do I Need? | 
|---|
    
| NGFW (Managed by PAN-OS or Panorama) |  | 
 
  
 
  
To mitigate a single-session DoS attack, you
would still 
Configure
DoS Protection Against Flooding of New Sessions in advance.
At some point after you configure the feature, a session might be
established before you realize a DoS attack (from the IP address
of that session) is underway. When you see a single-session DoS
attack, perform the following task to end the session, so that subsequent connection
attempts from that IP address trigger the DoS protection against
flooding of new sessions.