Installation & Initial Configuration
Monitoring events
FortiDDoS v3.2 Installation Guide
28-320-183686-20130401
20
•
64 bytes from 172.16.0.50: icmp_seq=3 ttl=64 time=0.220 ms
64 bytes from 172.16.0.50: icmp_seq=4 ttl=64 time=0.314 ms
64 bytes from 172.16.0.50: icmp_seq=5 ttl=64 time=0.260 ms
64 bytes from 172.16.0.50: icmp_seq=6 ttl=64 time=0.281 ms
64 bytes from 172.16.0.50: icmp_seq=7 ttl=64 time=0.206 ms
64 bytes from 172.16.0.50: icmp_seq=87 ttl=64 time=0.275 ms
64 bytes from 172.16.0.50: icmp_seq=88 ttl=64 time=0.336 ms
64 bytes from 172.16.0.50: icmp_seq=89 ttl=64 time=0.192 ms
64 bytes from 172.16.0.50: icmp_seq=90 ttl=64 time=0.192 ms
64 bytes from 172.16.0.50: icmp_seq=91 ttl=64 time=0.247 ms
64 bytes from 172.16.0.50: icmp_seq=92 ttl=64 time=0.172 ms
64 bytes from 172.16.0.50: icmp_seq=93 ttl=64 time=0.284 ms
--- 172.16.0.50 ping statistics ---
100 packets transmitted, 14 received, 86% packet loss, time
11253ms
rtt min/avg/max/mdev = 0.172/0.270/0.503/0.082 ms
The line above mentions that 14 responses were received, indicating 86 packets
were not received.
Monitoring events
The Monitor button on the screen shows the properties of all events that have occurred
for a selected period of time.
Event Monitor provides a comprehensive way to display network attacks so that users
can investigate them intuitively. Users can choose a particular date range or number of
events to be displayed. In addition, FortiDDoS devices provide categorized event
entries as well as VID and database choices so that users can see only the events of
their interest.
The events can be viewed at various levels as a table.
When packets are dropped by the appliance, you can see the cause of the drops and
other details as events in the event monitor.
Refer to the
DDoS Fundamentals Guide
for further details.
Showing traffic
The FortiDDoS user interface provides several granular traffic graphs. You can see the
traffic through each VID independently. The detailed description of these graphs is
available in the
FortiDDoS Web-based Manager Guide
. Corresponding to the ping test
“Performing a sanity test” on page 18
, activity will appear in the following and
several other graphs:
1
Show > Global > Card 1 > LAN 1 and WAN 1
2
Show > Current VID > Layer 3 > My Graphs > Protocols
3
Show > Current VID > Layer 4 > My Graphs > ICMP Types and Codes
.
Note:
The number of blocked requests may vary between 80 and 90 depending on when the
flood is started relative to the FortiDDoS device one second boundary.
Содержание FortiDDoS
Страница 1: ...FortiDDoS v3 2 Installation Guide ...
Страница 37: ......