Create a Post
Showing results for 
Search instead for 
Did you mean: 

FW Samp or penalty box

We have a number of AWS IP's hitting our GW's reglulaly with quite high connection rates on http and https (so can get through to our website).  Would you recommend using FW samp or Penalty box to deal with these type of attacks?

I have been warned against using Network quota as it has a major performance impact.



0 Kudos
1 Reply

Yes avoid the IPS signature Network Quota as that will kill practically all SecureXL acceleration in the firewall.

SecureXL penalty box only applies to an hosts with an excessive drop/block rate, so it won't apply to accepted HTTP/HTTPS connections to your websites.

The fw samp command can establish various quotas for accepted traffic that are efficiently enforced by SecureXL; I'd suggest a new-conn-rate quota combined with "track source".  Check out sk112454: How to configure Rate Limiting rules for DoS Mitigation


"Max Capture: Know Your Packets" Video Series
now available at
0 Kudos