<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DoS error messages - What do the numbers mean? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705142#M1025863</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome. Thanks Hoogen, I really appreciate you taking the time to enlighten me. I will rate your post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Feb 2007 12:42:12 GMT</pubDate>
    <dc:creator>mistr</dc:creator>
    <dc:date>2007-02-19T12:42:12Z</dc:date>
    <item>
      <title>DoS error messages - What do the numbers mean?</title>
      <link>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705138#M1025854</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;             I have a router using CBAC with error messages such as this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 16 01:05:11.676 CET: %FW-4-ALERT_ON: getting aggressive, count (15/500) current 1-min rate: 501&lt;/P&gt;&lt;P&gt;Feb 16 01:05:14.017 CET: %FW-4-ALERT_OFF: calming down, count (10/400) current 1-min rate: 369&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My understanding from docs online and also Richard Deal's book is that there were more than 500 connections started in the last minute which resulting in the first message, this then dropped below the low threshold of 400 resulting in the second message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I can find no mention anywhere on what the 'count (15/500)' and 'count (10/400)' numbers mean on each line. Is this how many sessions were blocked by CBAC in the last minute?&lt;/P&gt;&lt;P&gt;Can anyone enlighten me on this please?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705138#M1025854</guid>
      <dc:creator>mistr</dc:creator>
      <dc:date>2019-03-11T09:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: DoS error messages - What do the numbers mean?</title>
      <link>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705139#M1025857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rate of new connections is 15 in the last minute and has crossed the threshold of 500.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again the rate of new connection is 10 and at present droppped near threshold 400.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Hoogen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Feb 2007 16:13:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705139#M1025857</guid>
      <dc:creator>hoogen_82</dc:creator>
      <dc:date>2007-02-18T16:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: DoS error messages - What do the numbers mean?</title>
      <link>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705140#M1025859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hoogen,&lt;/P&gt;&lt;P&gt;          Thanks for the reply but I'm still a little confused. The error message says current 1-min rate:501 so how can there have been only 15 in the last minute?&lt;/P&gt;&lt;P&gt;Does that mean the rate of new connections has increased by 15 to 501 in the last minute? Ie in the previous minute it was 501-15=486?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2007 07:40:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705140#M1025859</guid>
      <dc:creator>mistr</dc:creator>
      <dc:date>2007-02-19T07:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: DoS error messages - What do the numbers mean?</title>
      <link>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705141#M1025862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you are right it has increased by 15 in the last minute and crossed the threshold of 500 and given you that log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Hoogen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate if I have helped out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2007 10:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705141#M1025862</guid>
      <dc:creator>hoogen_82</dc:creator>
      <dc:date>2007-02-19T10:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: DoS error messages - What do the numbers mean?</title>
      <link>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705142#M1025863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome. Thanks Hoogen, I really appreciate you taking the time to enlighten me. I will rate your post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2007 12:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dos-error-messages-what-do-the-numbers-mean/m-p/705142#M1025863</guid>
      <dc:creator>mistr</dc:creator>
      <dc:date>2007-02-19T12:42:12Z</dc:date>
    </item>
  </channel>
</rss>

