Monitoring Attack Filtering Using Cli Commands - Cisco SCE8000 Configuration Manual

Service control engine
Table of Contents

Advertisement

Monitoring Attack Filtering

Monitoring Attack Filtering Using CLI Commands

Use these commands to monitor attack detection and filtering:
Cisco SCE8000 Software Configuration Guide, Rel 3.1.6S
10-22
'protocol'
TCP
-
UDP
-
ICMP
-
other
-
'rate1' and 'rate2' are numbers
'duration' is a number.
'total-flows' is one of the following strings, depending on the attack action:
If 'action' is block: 'number' flows blocked.
-
If 'action' is report: attack comprised of 'number' flows.
-
'hw-filter'
-
If the attack was not filtered by a hardware filter: empty string
-
If the attack was filtered by a hardware filter: HW filters used, actual attack duration is probably
smaller than reported above, actual amount of flows handled is probably larger than reported
above.
show interface linecard 0 attack-detector
show interface linecard 0 attack-filter
show interface linecard 0 attack-filter query
show interface linecard 0 attack-filter current-attacks
show interface linecard 0 attack-filter don't-filter
show interface linecard 0 attack-filter force-filter
show interface linecard 0 attack-filter subscriber-notification ports
Chapter 10
Identifying and Preventing Distributed-Denial-Of-Service Attacks
OL-16479-01

Advertisement

Table of Contents
loading

Table of Contents