After Connection Limiting policies are configured, you might come across issues like the following:
No alerts are raised in the Manager.
Excess packets are not dropped or denied.
Hosts are not quarantined.
Connection Limiting rules can be configured with protocol types Alert only, Alert & Drop Excess Connections, Alert & Deny Excess Connections, and Alert & Quarantine.
Perform these steps to troubleshoot issues such as alerts not raised in the Manager, excess packets not dropped or denied, or hosts not quarantined after reaching the threshold value.
Make sure that the Connection Limiting policy rules are configured and applied to the Sensor interface.
From the Sensor CLI, run the
show inlinepktdropstat allcommand and check if theConn Limiting Pkt Drop Countis 0. This means that the configured threshold value is not reached. Only when the count reaches a threshold value, alerts are triggered in the Manager.Check whether the incoming traffic rate to the Sensor meets the Connection Limiting rule's threshold value. If it does not meet the threshold value, send the corresponding traffic rate.
Set a lower threshold value and check the active connections or connections per second.
Check if there is any firewall ignore rule for the source IP address configured in the Connection Limiting rule.
Go to Policy → Intrusion Prevension → Policy Types → Firewall Policies → <Firewall Policy> → Access Rules.
Select a policy and click Edit to view the rules of that policy or double-click on the row of the policy.
On the Access Rules tab, check if a source IP address's Response is set as Stateless Ignore or Ignore.
Check if the source IP address configured in the Connection Limiting rule is part of the Quarantine Exceptions list. Go to Devices → Global → IPS Device Settings → Quarantine → Default Port Settings to if source IP address is quarantined.
Considerations for GTI connection limiting and XFF feature
When you configure GTI and XFF for a connection limiting rule:
The Sensor cannot perform GTI lookup on the XFF IP address. The GTI-based connection limiting does not work when the XFF feature is enabled.
When the XFF feature is enabled, the Sensor expects that all HTTP flows should have XFF data in the HTTP header.
The Sensor supports connection limiting on XFF based on protocol-based connection limiting.
Alert Detection Matrix
The table briefs how alerts are detected based on the connection limiting type and XFF feature configuration.
Connection limiting type | XFF configuration | XFF or Non XFF tag traffic sent to Sensor | Proxy IP reputation | XFF IP | Alert detection |
|---|---|---|---|---|---|
Protocol | Disabled | Without XFF | - | Yes | |
Protocol | Enabled | With XFF | - | Yes | |
Protocol | Enabled | Without XFF | - | No | |
GTI | Disabled | Without XFF | - | Yes | |
GTI | Enabled | With XFF | Low risk | High risk | No |
GTI | Enabled | With XFF | High risk | Low risk | No |
GTI | Enabled | Without XFF | - | - | No |