I am looking to implement a service policy to protect against DoS SYN attacks. I have this config that I'm planning to apply (see below). Question is, it better to apply it to the outside interface (where no policy currently exists) or to the globa...