I see a new entry in DoS protection called "IP Flood"

Sophos v20 GA

I have never noticed this IP Flood protection before. It is not applied, but I cannot see it's activation anywhere in the GUI.

 All I see activatable is SYN, UDP, TCP and ICMP, Dropped source routed packets, Disable ICMP/ICMPv6 redirect packet, and ARP hardening



Edited TAGs
[edited by: emmosophos at 5:13 PM (GMT -7) on 8 Apr 2024]
Parents Reply
  • Hello,

    "IP Flood" is not a new feature and it's there since many releases (at least since v17.0+ like mentioned above).

    It was given in CLI along with DoS bypass rule CLI but never make it to GUI due to other priorities and that could be the reason it might not have been observed by many admins.

    Admin may want to use "IP flood" in a scenario where they would like to block all IP traffic regardless of whether it's TCP or UDP (which is given in GUI). Configuration part is in CLI and on GUI, drop counters can be seen.  

    Regards,

    Sanket Shah

    Director, Software Development, Sophos Firewall

Children
No Data