This article provides information on the issue where TDD detects attacks but fails to apply the appropriate blocking filters, allowing the attack to proceed without being blocked.
When the issue occurs, the mitigation application alert indicates that it attempted to apply the filters, but the filter application fails.
When TDD detects an attack but fails to apply the blocking filters, the following configuration issues could be the cause:
Incorrect Actions on Mitigation Alerts:
1) Ensure that the Mitigation Application and Mitigation Removal Alerts have only the ‘Corero Autonomic Response’ action configured.
2) Adding other actions, such as ‘Send Email’, introduces additional processing load and delays, which may cause the mitigation to fail.
3) Remove any Send Email or additional actions from these alerts. Instead, use a separate DDoS Incident Alert for sending email notifications.
Incorrect Device Configuration:
1) Verify that the list of devices under the Mitigation Application and Removal Alerts includes only the correct MX routers.
2) The alert should target only the intended MX routers.
3) Remove any extra devices (e.g., duplicated or unrelated devices), as having additional devices causes unnecessary retries and processing delays, which can prevent timely filter application.
By applying these changes, the system will focus solely on applying mitigation filters to the correct devices without additional processing, ensuring reliable and timely attack blocking.