Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Dos and Spoof Protection - Numbers

I want to enable Spoff Protection, do I need to be careful?

About DoS Settings, how do you work? Enable everything (SYN Flood, UDP, TCP, ICMP)? What are the recommended numbers to configure? Is the SOPHPOS standard the recommended numbers?



This thread was automatically locked due to age.
Parents
  • Hi Tiago,

    It would depend on what is the number to concurrent sessions/source in your network behind XG. You can configure a threshold of 1500 packet rate/source. Please do not configure any value on TCP Flood, leave it as default. 

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply
  • Hi Tiago,

    It would depend on what is the number to concurrent sessions/source in your network behind XG. You can configure a threshold of 1500 packet rate/source. Please do not configure any value on TCP Flood, leave it as default. 

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Children