HPE Aruba Networking & ProVision-based
1833758 Members
2602 Online
110063 Solutions
New Discussion

Connection-rate filtering - virus throttle

 
Brad_199
Frequent Advisor

Connection-rate filtering - virus throttle

Has anyone used connection-rate filtering based on virus throttle?

Do you have any advice or suggestions about it?

2 REPLIES 2
Neil_Salmon
Advisor

Re: Connection-rate filtering - virus throttle

Yes, it works well, however:-

1. Plan which devices (interfaces) you want to throttle - probably not your DHCP, DNS or AD servers.

2. Start with the settings lowto you get a feel for the number of issues on your network or you will be overwhelmed with false-positives and lots of unhappy users.

 

 

Richard Litchfield
Respected Contributor

Re: Connection-rate filtering - virus throttle

Sometimes it gives a false positive. Torrent servers are the example I recall that were incorrectly flagged. Put it in notify mode initially, and check the logs:
I 03/13/14 03:01:03 00806 connfilt: Src IP 172.20.100.107 unblocked
W 03/13/14 02:59:57 00695 connfilt: Src IP 172.20.100.107 throttled, port B20
I 03/09/14 08:54:47 00806 connfilt: Src IP 172.20.100.106 unblocked
W 03/09/14 08:53:44 00695 connfilt: Src IP 172.20.100.106 throttled, port B7