I have to expand firewall capacity (max session) for ddos protectionIn my opinion, firewall is vulnerable to a session based attack ( like HTTP GET Flooding)For DDOS protection.. I consider three items1. remove the L4 in front of firewall (like fire...