
A protected zone is an object comprised of a group of IP addresses and/or subnets, and ports and protocols that provide a service and are protected as a single entity.
TPS can build a typical traffic rate threshold baseline to facilitate traffic rate limits by examining traffic rate for a zone profile for a set period. This is done by configuring “learning” in operational mode. Then, operational mode is used to monitor traffic. For more information, see Zone Operational Mode.
When suspicious behavior occurs, it is possible you may not want to take immediate drastic actions which could be detrimental to the quality of service (QOS) for customers. To address this concern, zones can be configured with escalation levels (up to 5) that allow you to fine tune mitigation actions to be responsive to traffic conditions.
Detection and mitigation, the two primary actions for DDoS mitigation, can be handled by one device. When the detector identifies a risk that needs to be mitigated, it creates an incident. Depending on your network, a one device solution may or may not be optimal. An offering of the various types of deployments using Defend for device management is shown in Deployment and Topologies.
The following topics are covered: