DoS Sensors Being Triggered by Google
- June 9, 2015
- 5 replies
- 13927 views
So we're a pretty Google Apps heavy company. We use a lot of their services and recently it's all been running slow and I think I might have stumbled on what might be causing the problem but I'm unsure as why or how to correct it.
I have DoS policy (below) that, according to the logs, is getting triggered by Google and i'm unsure why. Port1 is our internet interface and I've got the policy applied to just DNS for some reason that eludes me right now. I don't want to remove it but I have no problems increasing the thresholds to see what happens. Also note, that Google services were extremely slow but mostly just for Chrome browser users which was really odd. If a user used IE or Firefox then everything seemed somewhat normal. I think Google is pushing something back to Chrome but why it's triggering a DoS sensor (udp_flood) that is running on udp/53 is beyond me. Attached is also a screenshot of the log message.
Has anybody seen this behavior? Suggestions?
edit 7 set status enable set interface "port1" set srcaddr "all" set dstaddr "all" set service "DNS"