FPR4140 - FTD Configuring Rate-Based Attack Prevention
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-31-2018 07:42 AM - edited 02-21-2020 08:10 AM
I am looking for some baseline config values for the Rate-Based Attack Prevention in Network Analysis Policy for a FTD in routed mode (Edge Firewall).
Coming from an ASA, the configurable values are totally different on the FTD and does not translate over at all.
I've searched a bit and have not come up with anyone sharing these, I know is dependent on the environment, however, there's also be some sort of standard baseline.
Any assistance will be appreciated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-05-2018 06:08 PM
Hi,
The way we do rate-based detection is dependent on the pre-processor configured as part of Intrusion Policy.
Basic overview of the feature is available in the config guide:
I hope this provides some guidance on the values to be configured.
