2.72. THRESHOLD

These log messages refer to the THRESHOLD (Threshold rule events) category.

2.72.1. conn_threshold_exceeded (ID: 05300100)

Default Severity
WARNING
Log Message
Connection threshold <description> exceeded <threshold>. Source IP: <srcip>. Closing connection
Explanation
The source ip is opening up new connections too fast.
Firewall Action
closing_connection
Recommended Action
Investigate worms and DoS attacks.
Revision
1
Parameters
description
threshold
srcip
Context Parameters
Rule Name

2.72.2. reminder_conn_threshold (ID: 05300101)

Default Severity
INFORMATIONAL
Log Message
Reminder: Connection threshold <description> exceeded <threshold>. Source IP: <srcip>.
Explanation
The source ip is still opening up new connections too fast.
Firewall Action
None
Recommended Action
Look through logs to see if the source ip has misbehaved in the past.
Revision
1
Parameters
description
threshold
srcip
Context Parameters
Rule Name

2.72.3. conn_threshold_exceeded (ID: 05300102)

Default Severity
NOTICE
Log Message
Connection threshold <description> exceeded <threshold>. Source IP: <srcip>
Explanation
The source ip is opening up new connections too fast.
Firewall Action
None
Recommended Action
Investigate worms and DoS attacks.
Revision
1
Parameters
description
threshold
srcip
Context Parameters
Rule Name

2.72.4. failed_to_keep_connection_count (ID: 05300200)

Default Severity
ERROR
Log Message
Failed to keep connection count. Reason: Out of memory
Explanation
The device was unable to allocate resources needed to include the connection in the connection count kept by threshold rules. The connection will not be included in the connection count.
Firewall Action
None
Recommended Action
Check memory consumption.
Revision
1
Context Parameters
Connection

2.72.5. failed_to_keep_connection_count (ID: 05300201)

Default Severity
ERROR
Log Message
Failed to keep connection count. Reason: Out of memory
Explanation
The device was unable to allocate resources needed to include the connection in the connection count kept by threshold rules. Since there exist protect actions that are triggered by thresholds on the number of connections, the connection will be closed.
Firewall Action
close
Recommended Action
Check memory consumption.
Revision
1
Context Parameters
Connection

2.72.6. threshold_conns_from_srcip_exceeded (ID: 05300210)

Default Severity
NOTICE
Log Message
The number of connections matching the rule and originating from <srcip> exceeds <threshold>.
Explanation
The number of connections matching the threshold rule and originating from a single host exceeds the configured threshold. Note: This log message is rate limited via an exponential back-off procedure.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
threshold
srcip
[username]
Context Parameters
Rule Name

2.72.7. threshold_conns_from_srcip_exceeded (ID: 05300211)

Default Severity
NOTICE
Log Message
The number of connections matching the rule and originating from <srcip> exceeds <threshold>.
Explanation
The number of connections matching the threshold rule and originating from a single host exceeds the configured threshold. The configured protective measures will be triggered. Note: This log message is rate limited via an exponential back-off procedure.
Firewall Action
protect
Recommended Action
None
Revision
1
Parameters
threshold
srcip
[username]
Context Parameters
Rule Name

2.72.8. threshold_conns_from_filter_exceeded (ID: 05300212)

Default Severity
NOTICE
Log Message
The number of connections matching the rule exceeds <threshold>. The Offending host is <srcip>.
Explanation
The number of connections matching the threshold rule exceeds the configured threshold. Note: This log message is rate limited via an exponential back-off procedure.
Firewall Action
None
Recommended Action
None
Revision
1
Parameters
threshold
srcip
[username]
Context Parameters
Rule Name

2.72.9. threshold_conns_from_filter_exceeded (ID: 05300213)

Default Severity
NOTICE
Log Message
The number of connections matching the rule exceeds <threshold>. The Offending host is <srcip>.
Explanation
The number of connections matching the threshold rule exceeds the configured threshold. The configured protective measures will be triggered. Note: This log message is rate limited via an exponential back-off procedure.
Firewall Action
protect
Recommended Action
None
Revision
1
Parameters
threshold
srcip
[username]
Context Parameters
Rule Name