This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Find source and destination of TCP and UDP DOS floods

I enabled DOS Protection and since then every minute sophos is droping some TCP traffic and sometimes UDP, I'm sure Im not getting attacked and just need to add a DOS bypass rule. My question is where in Sophos XG v18 can in find the Source and destination details of traffic that has been dropped because of the DOS protection. FYI, I've never used a firewall before and my first one is this so sorry it its a basic question. I can see logs and current activity and sure there must be some way to filter it to find this but not sure how. 



This thread was automatically locked due to age.
Parents
  • Hi  

    from Intrusion Prevention >> DoS Attacks

    DoS attack status allows you to see if traffic limits have been applied and the amount of data dropped after the limit has been exceeded. The firewall applies the traffic limits specified in DoS settings and logs the corresponding events. Data is available for the source and destination in real-time.

    • To view the attack details, click an attack type.
    • When you click on attack type, it will pop up a window and will provide flooder IP if the system detects it.

    For Configuration and in-depth details, I would recommend you to check the article - https://community.sophos.com/kb/en-us/123182

  • Hi Keyur,

    Thanks for the quick reply, that will definitely help with UDP.

    For TCP Flood i noticed that in your picture and also on my firewall that the hyperlink to view the details is not available. Is there anything for the TCP Flood side?

Reply
  • Hi Keyur,

    Thanks for the quick reply, that will definitely help with UDP.

    For TCP Flood i noticed that in your picture and also on my firewall that the hyperlink to view the details is not available. Is there anything for the TCP Flood side?

Children