Traffic Being Blocked Because Of DoS Attack

|
  • 290
  • 6

Issue Description

Customer’s PC block by NGAF because of DDoS blocking. Customer already formatted the PC in order to make sure it is clean but still being blocked.

Handling Process

1. Go to Report center check DoS Attack log.
2. Found that the IP has been blocked because of number packets exceeds the thershold of UDP flooding.
3.Go to Policies > Network Security > Anti-Dos/DDoS, select the outbound policy and change the UDP flooding threshold to 6000 packets/sec on Defense Against DoS/DDoS Attack.

Root Cause

Intranet users have excessive number of packets, it triggered the Anti-DoS policy and being blocked.

Solution

Appropriately increase the UDP flooding threshold on outbound of Anti-Dos policy.
Faisal Posted 21 Aug 2020 08:11
  
Thank you very much for the information ...
Faisal Posted 23 Oct 2020 08:42
  
Nice article ...
Faisal Posted 18 Dec 2020 10:15
  
Great info ...
Ellechar Lv4Posted 26 Jan 2021 17:01
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 19 Mar 2021 07:19
  
Very informative …
Faisal Posted 04 Jun 2021 12:17
  
Nice guidance ...

I want to write a case
Doc ID: 2475
Author: CTI Jimy
Updated: 2019-12-24 10:16
Version: