Is there a way with Sophos UTM 9 to limit the connections per second for web requests? Preferably per requesting IP address.
This thread was automatically locked due to age.
Hi Tim,
Are you looking to restrict source packets per second? Then please go to Network Protection> Intrusion Prevention > AntiDoS/ Flooding. Refer https://community.sophos.com/kb/hu-hu/115154 for further help.
Thanks
Sachin Gurung
Team Lead | Sophos Technical Support
Knowledge Base | @SophosSupport | Video tutorials
Remember to like a post. If a post (on a question thread) solves your question use the 'This helped me' link.
Tim, please share the reason for this question - what problem are you trying to address with this?
Cheers - Bob
Tim, please share the reason for this question - what problem are you trying to address with this?
Cheers - Bob
It's really about throttling legitimate traffic, like clients that get impatient and repeatedly hit submit. Or as is sometimes the case, when they drop a stack of papers on their keyboard. It can also be when someone is accessing the API and spin up too many processes. Not really looking at intentionally malicious traffic.
That's what Aditya posted about above. WebAdmin uses a different metaphor, more is under the covers and behind the scenes, but just keep asking questions and you'll deliver a great result.
Cheers - Bob
In the referenced article it says: "The ASG can protect against flooding by throttling connections that are not following the normal TCP/IP protocols." Later followed with: "On the other hand, if you set the rate too low, your firewall might show some unpredictable behavior by blocking regular SYN (TCP) requests".
So, does it rate limit all TCP connection requests, or is it looking for specific types of malicious traffic?
TMG let me specify HTTP traffic connections per minute and we actually had users who could exceed the limit just filling out forms on websites and clicking next. We tweaked as necessary.
Two different things. See the 'Protocol Handling' section on the 'Advanced' tab in 'Firewall' for the first question in your last post.
Cheers - Bob