02.04.2019

FastNetMon threshold types

To achieve better DDoS detection FastNetMon offers number of threshold types. For each host (/32 for IPv4 and /128 for IPv6) in your network FastNetMon maintains set of counters for different traffic types. FastNetMon calculates all counter types for incoming and outgoing traffic.

Global counters:

  • Packets per second
  • Mbits per second
  • Flow per second (not available for sampled Netflow/IPFIX and sFlow)

Per protocol packet counters:

  • TCP packets per second
  • UDP packets per second
  • ICMP packets per second

Per protocol bandwidth counters:

  • TCP mbits per second
  • UDP mbits per second
  • ICMP mbits per second

You can use any of these counters to trigger DDoS alert. In table below you can find option to enable particular threshold and field name for setting threshold itself .

Option to enableThreshold value name
ban_for_ppsthreshold_pps
ban_for_bandwidththreshold_mbps
ban_for_flowsthreshold_flows
ban_for_tcp_ppsthreshold_tcp_pps
ban_for_udp_ppsthreshold_udp_pps
ban_for_icmp_ppsthreshold_icmp_pps
ban_for_tcp_bandwidththreshold_tcp_mbps
ban_for_udp_bandwidththreshold_udp_mbps
ban_for_icmp_bandwidththreshold_icmp_mbps

To set threshold for some hostgroup you can use following syntax:

For example, to enable limit by UDP packets per second you can use: