Simlpe, all I need, it's a configure what to log and count in policies, something like this:
policies {
from-zone local to-zone vpn {
policy to_vpn {
match {
source-address any;
destination-address any;
application any;
}
then {
permit;
log {
session-init;
session-close;
}
count {
alarm per-second-threshold 1 per-minute-threshold 4;
}
}
}
}
}