09-23-2012 06:21 AM - edited 03-07-2019 09:02 AM
Referring to following link, it provides a list of default value for firewall setting,
I would like to know how to determine any appropriated DoS parameters adjusted to your network's normal behavior, and prevent any DoS protection mechanism, causing application failures, poor network performance, and high CPU utilization on the Cisco IOS Firewall router.
Will those default value be the most acceptable levels on balancing between network's normal behavior and DoS protection?
Does anyone have any suggestions?
Thanks in advance for any suggestions
ip inspect max-incomplete high value (default 500)
ip inspect max-incomplete low value (default 400)
ip inspect one-minute high value (default 500)
ip inspect one-minute low value (default 400)
ip inspect tcp max-incomplete host value (default 50) [block-time minutes (default 0)]
09-23-2012 08:55 AM
Hello Oem,
if you haven't already done you should post your thread under security / firewall forum section
Hope to help
Giuseppe
09-23-2012 02:52 PM
Hi Oem,
Defines the number of half-open (incomplete) sessions that will cause the router to start deleting half-complete sessions (the high value) and stop deleting half-complete sessions (the low value). The
no version restores the default value
Defines the connection establishment rate at which the router starts deleting half-complete sessions (the high value) and stops deleting half-complete sessions (the low value). The no version restores the default value.
Defines the number of half-open (incomplete) sessions that will cause the router to start deleting half-complete sessions (the high value) and stop deleting half-complete sessions (the low value). The no version restores the default value
http://www.juniper.net/techpubs/software/erx/junose700/swcmdref-a-m/html/i-commands127.html
http://www.juniper.net/techpubs/software/erx/junose700/swcmdref-a-m/html/i-commands125.html
hope this helps.
please rate if this helps
thanks
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: