How To Enable Specific-Ip Detection For The Tcp Protocol Only For All Attack Directions - Cisco SCE 8000 10GBE Software Configuration Manual

Table of Contents

Advertisement

Chapter 12
Identifying and Preventing Distributed Denial-of-Service Attacks

How to Enable Specific-IP Detection for the TCP Protocol Only for all Attack Directions

From the SCE(config if)# prompt, enter:
Command
attack-filter protocol TCP
How to Enable Specific-IP Detection for the TCP Protocol for Port-Based Detections Only for
Dual-Sided Attacks
From the SCE(config if)# prompt, enter:
Command
attack-filter protocol TCP dest-port specific
attack-direction dual-sided
How to Disable Specific-IP Detection for Protocols Other than TCP, UDP, and ICMP for all Attack
Directions
From the SCE(config if)# prompt, enter:
Command
no attack-filter protocol other
How to Disable Specific-IP Detection for ICMP for Single-Sided Attacks Defined by the Source IP
From the SCE(config if)# prompt, enter:
Command
no attack-filter protocol ICMP
attack-direction single-side-source
Configuring the Default Attack Detector
OL-30621-02
Options, page 12-12
How to Define the Default Action and Optionally, the Default Thresholds, page 12-13
How to Reinstate the System Defaults for a Selected Set of Attack Types, page 12-13
How to Reinstate the System Defaults for All Attack Types, page 12-14
Purpose
Enables specific-IP detection for the TCP
protocol only for all attack directions.
Purpose
Enables specific-IP detection for the TCP
protocol for port-based detections only for
dual-sided attacks.
Purpose
Disables specific-IP detection for protocols other
than TCP, UDP, and ICMP for all attack directions.
Purpose
Disable specific-IP detection for ICMP for
single-sided attacks defined by the source IP.
Cisco SCE 8000 10GBE Software Configuration Guide
Configuring Attack Detectors
12-11

Advertisement

Table of Contents
loading

Table of Contents