Download Print this page

Cisco ASA 5506-X Configuration Manual page 328

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

Defaults for Threat Detection
Defaults for Threat Detection
Basic threat detection statistics are enabled by default.
The following table lists the default settings. You can view all these default settings using the show
running-config all threat-detection command.
For advanced statistics, by default, statistics for ACLs are enabled.
Table 15-2
Packet Drop Reason
Scanning attack detected
Incomplete session detected such as
TCP SYN attack detected or no data
UDP session attack detected
(combined)
Denial by ACLs
Interface overload
Configure Threat Detection
Basic threat detection statistics are enabled by default, and might be the only threat detection service that
you need. Use the following procedure if you want to implement additional threat detection services.
Cisco ASA Series Firewall CLI Configuration Guide
15-4
Basic Threat Detection Default Settings
DoS attack detected
Bad packet format
Connection limits exceeded
Suspicious ICMP packets
detected
Basic firewall checks failed
Packets failed application
inspection
Trigger Settings
Average Rate
100 drops/sec over the last 600
seconds.
80 drops/sec over the last 3600
seconds.
5 drops/sec over the last 600
seconds.
4 drops/sec over the last 3600
seconds.
100 drops/sec over the last 600
seconds.
80 drops/sec over the last 3600
seconds.
400 drops/sec over the last 600
seconds.
320 drops/sec over the last
3600 seconds.
400 drops/sec over the last 600
seconds.
320 drops/sec over the last
3600 seconds.
2000 drops/sec over the last
600 seconds.
1600 drops/sec over the last
3600 seconds.
Chapter 15
Threat Detection
Burst Rate
400 drops/sec over the last 20
second period.
320 drops/sec over the last 120
second period.
10 drops/sec over the last 20
second period.
8 drops/sec over the last 120
second period.
200 drops/sec over the last 20
second period.
160 drops/sec over the last 120
second period.
800 drops/sec over the last 20
second period.
640 drops/sec over the last 120
second period.
1600 drops/sec over the last 20
second period.
1280 drops/sec over the last 120
second period.
8000 drops/sec over the last 20
second period.
6400 drops/sec over the last 120
second period.

Hide quick links:

Advertisement

loading