Forum Discussion

jack_10574's avatar
jack_10574
Icon for Nimbostratus rankNimbostratus
Aug 02, 2016

F5 AFM Reporting --> Dos overview

Hi all

 

i have go through the AFM security --> Reporting --> DOS --> network . I found some log here but i am not understand how the log are trigger . Can anyone explain to me base on the screen shoot what is the meaning virtual server = aggregate ? what means aggregate for virtual server ?

 

just to note , in Dos profile i am set detection threshold = 1000 pps individually for TCP RST flood and UDP =1000 pps as well.. but every attack ID are showing number with less than 100 ... Isnt it only trigger when more than 1000 pps ?

 

please advice

 

2 Replies

  • Thats interesting because i have fine tuned dos settings and my AFM DoS reporting doesn't show anything. do you happen to have a test VIP thats hitting this thresholds?

     

    Can you drill down on one of the attack ID's to get more information... the chart you have displayed is the top total requests, did the PPS detect threshold get triggered?

     

  • We need clarification because I also see nothing when I visit ecurity --> Reporting --> DOS --> network. My Threshhold 500pps rate limit 100000pps