2.44. THRESHOLD
These log messages refer to the THRESHOLD (Threshold rule events) category.
2.44.1. conn_threshold_exceeded (ID: 05300100)
Default Severity
WARNING
Log Message
Connection threshold <description> exceeded <threshold>. Source IP:
<srcip>. Closing connection
Explanation
The source ip is opening up new connections too fast.
Gateway Action
closing_connection
Recommended Action
Investigate worms and DoS attacks.
Revision
1
Parameters
description
threshold
srcip
Context Parameters
Rule Name
2.44.2. reminder_conn_threshold (ID: 05300101)
Default Severity
INFORMATIONAL
Log Message
Reminder: Connection threshold <description> exceeded <threshold>.
Source IP: <srcip>.
Explanation
The source ip is still opening up new connections too fast.
Gateway Action
None
Recommended Action
Look through logs to see if the source ip has misbehaved in the past.
Revision
1
Parameters
description
threshold
srcip
Context Parameters
Rule Name
2.44.3. conn_threshold_exceeded (ID: 05300102)
Default Severity
NOTICE
Log Message
Connection threshold <description> exceeded <threshold>. Source IP:
<srcip>
Explanation
The source ip is opening up new connections too fast.
Gateway Action
None
2.44. THRESHOLD
Chapter 2. Log Message Reference
439
Summary of Contents for DFL-210 - NetDefend - Security Appliance
Page 25: ...List of Tables 1 Abbreviations 28 25...
Page 26: ...List of Examples 1 Log Message Parameters 27 2 Conditional Log Message Parameters 27 26...
Page 36: ...1 3 Severity levels Chapter 1 Introduction 36...
Page 195: ...2 12 6 route_removed ID 01100006 Chapter 2 Log Message Reference 195...
Page 409: ...2 40 19 scp_failed_not_admin ID 04704000 Chapter 2 Log Message Reference 409...
Page 476: ...2 49 14 zd_block ID 03800014 Chapter 2 Log Message Reference 476...