Alternatively, you can choose the Protect action and specify
a
DoS profile where you
set the thresholds (sessions or packets per second) that trigger
an alarm, activate a protective action, and indicate the maximum
rate above which all new connections are dropped. Thus, you can
control the number of sessions between interfaces, zones, addresses,
and countries based on aggregate sessions or source and/or destination
IP addresses. For example, you can control traffic to and from certain
addresses or address groups, or from certain users and for certain
services.