Flood Detection (8910001)
Options
Hello.
Today I've visited LOG on my ZyWall 100, and saw warning lines:
Today I've visited LOG on my ZyWall 100, and saw warning lines:
Category: ADP
from Any to ZyWALL, [type=Flood-Detection(8910001)] TCP Flood TCP Flood Action: Block Severity: medium [count=2]
All of the floods are blocked, but there are thousands of strings in the LOG and CPU loads for 90%.
What Can I do? Give me suggestions, please.
All of the floods are blocked, but there are thousands of strings in the LOG and CPU loads for 90%.
What Can I do? Give me suggestions, please.
0
All Replies
-
Hi @follet,If it have large amount attack traffic continuously, we would suggest to disable the flooding log temporarily,because the device keep on writing the log, which will consume the CPU loading.
Assume those traffic have specific pattern, you also can try to block by IDP custom signature.
0
Categories
- All Categories
- 384 Beta Program
- 2.1K Nebula
- 117 Nebula Ideas
- 80 Nebula Status and Incidents
- 5.1K Security
- 76 USG FLEX H Series
- 247 Security Ideas
- 1.3K Switch
- 69 Switch Ideas
- 907 WirelessLAN
- 34 WLAN Ideas
- 5.9K Consumer Product
- 209 Service & License
- 335 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.9K FAQ
- 898 Nebula FAQ
- 415 Security FAQ
- 234 Switch FAQ
- 205 WirelessLAN FAQ
- 46 Consumer Product FAQ
- 137 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 73 About Community
- 62 Security Highlight