This section provides the high-level steps, with examples, on how to block a host that is launching a DoS attack.
Keep the inline Sensor in learning mode for 48 hours so that normal traffic pattern is learnt.
Send some particular type of traffic from selected IP addresses through the Sensor during the learning mode, that is, for the first 48 hours.
For example, send 5 Mbps of UDP packet type to the Sensor from selected IP address, such as
10.10.0.1, 198.19.0.2, 120.100.10.1, 100.10.10.11 and 99.40.10.30.Note
The Sensor automatically switches to detection mode after the first 48 hours.
Enable blocking for the corresponding attack in the DoS policy.
For example, enable blocking for Inbound UDP Packet Volume Too High attack definition in the DoS policy.
Set the maximum value on the Sensor using the CLI command:
set dospreventionseverity <packet type> <direction> <value>Send significantly more similar traffic from the selected IP address through the Sensor than what was sent during the learning mode.
For example, send more than 50 Mbps traffic from the IP address 10.10.0.1. Now, the traffic from the IP address 10.10.0.1 is blocked.