Hey guys,
I am having a Friday afternoon brain fart.
I am trying to configure the DOS TCP Flood settings in XG. Only using the Source side (destination not enabled)
If I leave them as standard and enable I get massive TCP Flood Trigger (set to 12000 / 100) and when checking the Firewall logs the traffic is blocked due to DOS Attack. Many of the IPs belong to Microsoft Azure and Office 365
I have allowed DNS 53 and 443 (UDP) in a DOS Bypass.
As we have about 250 Users accessing O365 from the LAN is the TCP Flood triggering due to the amount of traffic? Would I need to increase both Packet Rate Per Source and also Burst Rate per Source?
Seems as soon as I enable the TCP settings many blocks begin.
This thread was automatically locked due to age.