How does the IG200/IG2000 deal with traffic ‘spikes’?
A spike can be described as an anomalous increase in traffic that exceeds one of many preset thresholds. This might be best described by example. Suppose a server performs an automatic backup on Friday at 11:00 p.m. This would create an increase in outbound TCP traffic. The TCP packet threshold will not likely be reached because only a single connection is involved. The backup application probably uses a specific TCP port number, which has an outbound packet threshold assigned. The administrator should set this threshold accordingly to accommodate the traffic pattern of the backup. This packet threshold can be determined by viewing the profile collected by the IG200/IG2000 during previous backups. If the administrator is concerned about abuse on this port, the threshold can be set low (or to zero) during non-backup days.