Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Jon_Dyke
Contributor

FW Samp or penalty box

We have a number of AWS IP's hitting our GW's reglulaly with quite high connection rates on http and https (so can get through to our website).  Would you recommend using FW samp or Penalty box to deal with these type of attacks?

I have been warned against using Network quota as it has a major performance impact.


Thanks

Jon

0 Kudos
1 Reply
Timothy_Hall
Legend Legend
Legend

Yes avoid the IPS signature Network Quota as that will kill practically all SecureXL acceleration in the firewall.

SecureXL penalty box only applies to an hosts with an excessive drop/block rate, so it won't apply to accepted HTTP/HTTPS connections to your websites.

The fw samp command can establish various quotas for accepted traffic that are efficiently enforced by SecureXL; I'd suggest a new-conn-rate quota combined with "track source".  Check out sk112454: How to configure Rate Limiting rules for DoS Mitigation

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events