Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
James_Trout
Explorer

SmartEvent - High rate of Blocked Connections - How does it work/best practice?

We keep hitting our max connections for "High Rate of Blocked Connections" within smart event > DOS. We have upped the limit for now but I would like to understand more on how this works?

I believe the default for this rule is Origin which is the firewall itself. When triggered what does the event do, it seems to reject connections on the top source, is this correct?

Does anyone else use this rule and could you advise on best practices for this rule or what other users settings are? for example: Should we change the distinct event candidates away from Origin?

I have looked at the admin guides but feel it doesnt explain what is actually happening.

 

Thanks 

Jim

0 Kudos
2 Replies
G_W_Albrecht
Legend
Legend

Maybe this can help: sk112454: How to configure Rate Limiting rules for DoS Mitigation 

CCSE CCTE CCSM SMB Specialist
0 Kudos
James_Trout
Explorer

Thanks, I assume these are manual rules and not the Smart Event. I still am yet to understand the actual rule itself?

Can anyone share there settings for this rule or explain how it works?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events