Rate Limiting is a defense against DoS (Denial of Service) attacks. Rate Limiting rules allow to limit traffic coming from specified sources, or sent to specified destination and using specific services.
Rate limiting is enforced by SecureXL on these:
For additional information, see sk112454: How to configure Rate Limiting rules for DoS Mitigation.
Important - Configuration is supported only from the Command Line.
Use the commands below to configure Rate Limiting for DoS Mitigation:
fw sam_policy
' and 'fw6 sam_policy
' (you must use the parameter "quota <Quota Filter Arguments>")g_fwaccel dos config
' and 'g_fwaccel6 dos config
'To see some information related to DoS Mitigation, run these commands:
Command |
Description |
---|---|
|
Shows all SecureXL statistics (for IPv4 and IPv6 kernel modules. See: |
or
or
|
Shows SecureXL drop statistics only (for IPv4 and IPv6 kernel modules). See: |
|
Shows details of active policy rules in long format (for IPv4 and IPv6 kernel modules). |
|
Shows:
|
In addition, see SecureXL Debug.