AudioCodes Mediant 600 User Manual page 151

Voip media gateways analog & digital lines
Hide thumbs Also See for Mediant 600:
Table of Contents

Advertisement

User's Manual
Parameter
Index
CLI: rule-id
[IDSRule_RuleID]
Reason
CLI: reason
[IDSRule_Reason]
Threshold Scope
CLI: threshold-scope
[IDSRule_ThresholdScope
]
Threshold Window
CLI: threshold-window
[IDSRule_ThresholdWindo
w]
Version 6.6
Table 12-2: IDS Rule Table Parameters
Defines the table row number for the rule.
Defines the type of intrusion attack (malicious event).
[0] Any = All events listed below are considered as attacks and
are counted together.
[1] Connection abuse (default) = TLS authentication failure.
[2] Malformed message =
Message exceeds a user-defined maximum message length
(50K)
Any SIP parser error
Message Policy match (see Configuring SIP Message Policy
Rules)
Basic headers not present
Content length header not present (for TCP)
Header overflow
[3] Authentication failure =
Local authentication ("Bad digest" errors)
Remote authentication (SIP 401/407 is sent if original
message includes authentication)
[4] Dialog establish failure =
Classification failure (see Configuring Classification Rules)
Routing failure
Other local rejects (prior to SIP 180 response)
Remote rejects (prior to SIP 180 response)
[5] Abnormal flow =
Requests and responses without a matching transaction user
(except ACK requests)
Requests and responses without a matching transaction
(except ACK requests)
Defines the source of the attacker to consider in the device's
detection count.
[0] Global = All attacks regardless of source are counted together
during the threshold window.
[2] IP = Attacks from each specific IP address are counted
separately during the threshold window.
[3] IP+Port = Attacks from each specific IP address:port are
counted separately during the threshold window. This option is
useful for NAT servers, where numerous remote machines use
the same IP address but different ports. However, it is not
recommended to use this option as it may degrade detection
capabilities.
Defines the threshold interval (in seconds) during which the device
counts the attacks to check if a threshold is crossed. The counter is
automatically reset at the end of the interval.
The valid range is 1 to 1,000,000. The default is 1.
151
Description
Mediant 600 & Mediant 1000
12. Security

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mediant 1000

Table of Contents