Forum Discussion

ipman_1988_5418's avatar
ipman_1988_5418
Icon for Nimbostratus rankNimbostratus
Aug 15, 2017

AFM Learn-Only Signatures Dropping Traffic

I was under the impression initially that if you had these dynamic signatures set to learn-only you weren't going to drop traffic. I have set all of these vectors to enforced and it looks like the event logs show drops so is this in fact enforcing/dropping?

 

 

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    ipman,

     

    What you are seeing in the logs is right, the Attack Vectors are enforced so AFM is dropping traffic. The Learn Only mode you are seeing is referencing Dynamic Signatures. Here, the AFM is doing Behavioural analysis and creating Dynamic Signatures on the fly, if required. Looking at your logs it's not triggering a Dynamic Signature, rather the default BADACK attack vector.

     

    See

     

    Detecting Dynamic DoS Attacks

     

    Hope this helps,

     

    N