Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LostBoY
Advisor

Excessive Denies from a source ip

We have recently set up SOC monitoring for our R80.40 Gateways. There have been constant alerts related to excessive denies from a single source or excessive prevent action logged by IPS.

My query is if the action is drop/reject or prevent for either neutral reputation or malicious reputation... are these kind of alerts relevant enough to be addressed or they are best left unattended considering Firewall on its own is taking care of these.

Or do i need to worry about Firewall Health or look at if a certain benchmark has been breached from a single source . for example : if there are more than150k or 100k hits from a single source then i should check certain things such as Firewall Health , Memory etc. ?

0 Kudos
2 Replies
the_rock
Legend
Legend

You can make IPS exception for it, or SAM rule to block it, but it sounds like the firewall is doing its job.

Timothy_Hall
Champion
Champion

It sounds like the firewall is doing its job. However if you are concerned about all the drops coming from single source IP address, this is a great use case for enabling the SecureXL penalty box which can very efficiently start blocking this type of traffic, and avoid the overhead of a full rulebase lookup for every dropped packet.  See section 9 of this SK:

sk112454: How to configure Rate Limiting rules for DoS Mitigation (R80.20 and higher)

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events