6.5.7. Procedure – Connection rate limiting

Purpose: 

To limit the maximum rate of new connections to prevent Denial of Service (DoS) attacks, configure the connection rate limiting options on the Limits tab of the firewall rule. You can specify the number of connections that Application-level Gateway accepts within a given time period. Connection requests above this maximum rate are denied.

Steps: 

  1. Navigate to <Host> > Application-level Gateway > Firewall Rules.

  2. Select the rule to edit, then click Edit > Limits

  3. Click Enable rate limiting, then set the maximum number of permitted connection requests (per second) in the Maximum average match rate field.

    Connection rate limiting

    Figure 6.45. Connection rate limiting

    • To limit the rate of connections based on the destination in the connection requests, select Match packet destination IP address.

    • To limit the rate of connections based on the source of the connection requests, select Match packet source IP address.

  4. Set other parameters as needed for your environment.