You can create the Connection Limiting policy at the admin domain level. You can configure the Connection Limiting policy with the monitoring ports in SPAN, tap, or inline modes.
Note
The response actions differ for SPAN and tap modes. In these modes, the Sensor cannot block the connections or quarantine the hosts.
The connections are limited based on the predefined threshold value. The threshold value is defined as connections per second or active connections. For example, if you define 1 connection per second as the threshold value, then, 10 connections are allowed per 10 seconds. So, if there are 10 connections in the first second, all the other connections from the second to the tenth second are dropped. On the other hand, if you have 1 connection for each second, all the 10 connections until the tenth second are allowed. This is also known as traffic sampling.
Note
The minimum and maximum threshold values are 1 connection per second and 65535 connections per second respectively.
After you create a Connection Limiting policy, you can assign it to a Sensor's interfaces and subinterfaces.
Note
These Sensor resources must be of type VLAN or CIDR. You can assign the policy to these levels depending upon the configuration of the monitoring ports.
After you assign the Connection Limiting policy, the Sensor limits the connections based on the configured threshold values. An alert is sent each time the connection exceeds the defined threshold value. You can have any of the following response actions for that connection:
Alert only
Alert and drop excess connections
Alert and deny excess connections
Alert and quarantine