DefensePro User Guide
Security Configuration
140
Document ID: RDWR-DP-V0602_UG1201
Mitigation Actions
When the protection is enabled and the device detects that a DNS-flood attack has started, the
device implements the Mitigation Actions in escalating order—in the order that they appear in the
group box. If the first enabled Mitigation action does not mitigate the attack satisfactorily (after a
certain Escalation Period), the device implements the next more-severe enabled Mitigation Action—
and so on. As the most severe Mitigation Action, the device always implements the Collective Rate
Limit, which limits the rate of all DNS queries to the protected server.
Enable Signature Challenge Specifies whether the device challenges suspect DNS queries that
match the real-time signature.
Default: Enabled
Note:
DefensePro challenges only A and AAAA query types.
Enable Signature Rate Limit Specifies whether the device limits the rate of DNS queries that
match the real-time signature.
Default: Enabled
Enable Collective Challenge Specifies whether the device challenges all unauthenticated DNS
queries to the protected server.
Default: Enabled
Note:
DefensePro challenges only A and AAAA query types.
Enable Collective Rate Limit (Read-only) The device limits the rate of all DNS queries to the
protected server.
Value: Enabled
Advanced Parameters
These settings affect periodic attack behavior. The settings are used to effectively detect and block
these attack types.
Duration of Non-attack
Traffic in Analysis State
The time, in seconds, at which the degree of attack falls below and
stays below the hard-coded threshold in the Analysis state. When the
time elapses, DefensePro declares the attack to be terminated.
Values:
•
0—DefensePro declares the attack to be terminated
immediately.
•
1–30
Default: 0
Duration of Non-attack
Traffic in Blocking State
The time, in seconds, at which the degree of attack falls below and
stays below the hard-coded threshold in the Blocking state. When the
time elapses, DefensePro declares the attack to be terminated.
Values:
•
0—DefensePro declares the attack to be terminated
immediately.
•
1–300
Default: 10
Note:
There is no typical use case for reducing the value from the
default.
Table 69: DNS Flood Protection Global Parameters
Parameter
Description
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...