Hi,
DoS protection IS a UTM feature and part of IPS (combined with rates). Of course it will affect performance, but what are we talking about here, in terms of WAN throughput? Or do you use the FGT for heavy internal traffic as well?
The FG-620B is rated at 16 Gbps firewall throughput and 1 Gbps IPS throughput. That should be sufficient for most WAN lines.
Design hints:
- be sure to select only relevant traffic in the DoS sensor, i.e. TCP only, HTTP/port 80
- scanning SSL / HTTPS as well will cost more
- if the CPU load exceeds 50% you might consider putting the DoS sensor into a DoS interface policy. IPS on an interface takes action very early, before firewalling or AV processing, and thus preserves ressources.
But frankly I cannot imagine that a DoS sensor on a WAN line challenges the 620B a bit.
Ede Kernel panic: Aiee, killing interrupt handler!