FortiDDoS
FortiDDoS protects from both known and zero day attacks with very low latency. It’s easy to deploy and manage, and includes comprehensive reporting and analysis tools.
cbenejean
Staff
Staff
Article Id 196292
Description
There is no recommendation to set the SPP switching threshold, it all depends uniquely on the traffic that passes through the SPP.

In current version 4.1 there is no precise way of finding the exact measurement of traffic that is flowing through the SPP.

In future release of 4.2 a graph will be added that calculates the total of traffic flowing through each SPP which will help to judge what thresholds should be placed in this threshold field.

Solution
Setting SPP Policy Switching Thresholds

SPP Policy Thresholds are the sum of the inbound + outbound packet traffic to that SPP Policy (subnet).

We need to calculate the sum of the Inbound + Outbound SPP packet traffic for the protocols used in that SPP:

We do not show protocols 6 or 17 in Thresholds so we need to deduce them.

For the in-use protocols either:

- Look at the last/longest Traffic Statistics report that was run for the SPP (the Protocols Statistics page) or
- Look at the Protocol graphs for that SPP

For Statistics:

Sum the Inbound + Outbound packet rates for all Protocols you use (will show on the Protocol Statistics page)

For Graphs:

Look at a long graph period (week or month) and record the max numbers for inbound, then outbound for all Protocols in use.

Multiply the packet rate from above by 3. This follows the normal system recommendation for Layer 3 Threshold settings. This rate becomes the SPP Policy Switching Threshold.

That rate should be set as the Switching Threshold for all SPP Policies (subnets) in that SPP. The system will measure packet rates to each subnet and only alert on the specific subnet that exceeds the Switching Threshold.

If you need more fine-grained control of the alert and traffic statistics for a particular subnet, you should configure that single subnet in a separate SPP so that the SPP rates and subnet rates match.

Contributors