Skip to main content
cbenejean
Staff
Staff
January 29, 2018

Technical Tip: Most active source graph

  • January 29, 2018
  • 0 replies
  • 891 views

Description

 
This article describes why there are more packets/sec reported for the Most Active Source graph (see Most Active Source graph - FortiDDOS Handbook) compared to what the FortiDDoS is actually receiving/sending for that source and also compared to other graphs.


Scope

 

All FortiDDoS.


Solution

 
For TCP and DNS traffic, the MAS will add up both directions. Wherever a session is detected, it is associated with both inbound and outbound traffic to its source for Most Active Source. This is to catch the offending sources in a faster way. Since this client creates the session, the source can be identified and punished more rapidly.