How To Enable Specific-Ip Detection; Options; How To Enable Specific-Ip Detection For The Tcp Protocol Only For All Attack Directions - Cisco SCE2020-4XGBE-SM Configuration Manual

Software configuration guide
Table of Contents

Advertisement

Chapter 11
Identifying and Preventing Distributed-Denial-Of-Service Attacks

How to Enable Specific-IP Detection

By default, specific-IP detection is enabled for all attack types. You can configure specific IP detection
to be enabled or disabled for a specific, defined situation only, depending on the following options:

Options

The following options are available:
How to Enable Specific-IP Detection
Step 1
From the SCE(config if)# prompt, type attack-filter [protocol (((TCP|UDP) [dest-port
(specific|not-specific|both)])|ICMP|other)] [attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all)] and press Enter.

How to Enable Specific-IP Detection for the TCP Protocol Only for all Attack Directions

From the SCE(config if)# prompt, type attack-filter protocol TCP and press Enter.
Step 1
OL-7827-12
Options, page 11-9
How to Enable Specific-IP Detection, page 11-9
How to Enable Specific-IP Detection for the TCP Protocol Only for all Attack Directions, page 11-9
How to Enable Specific-IP Detection for the TCP Protocol for Port-based Detections Only for
Dual-sided Attacks, page 11-10
How to Disable Specific-IP Detection for Protocols Other than TCP, UDP, and ICMP for all Attack
Directions, page 11-10
How to Disable Specific-IP Detection for ICMP for Single-sided Attacks Defined by the Source IP,
page 11-10
For a selected protocol only.
For TCP and UDP protocols, for only port-based or only port-less detections.
For a selected attack direction, either for all protocols or for a selected protocol.
protocol — The specific protocol for which specific IP detection is to be enabled or disabled.
Default — all protocols (no protocol specified)
attack direction — Defines whether specific IP detection is enabled or disabled for single sided or
dual sided attacks.
Default — all directions
destination port (TCP and UDP protocols only) — Defines whether specific IP detection is enabled
or disabled for port-based or port-less detections.
Default — both port-based or port-less
Use the no form of the command to disable the configured specific-IP detection.
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
Configuring Attack Detectors
11-9

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sce 2000Sce 1000

Table of Contents