How To Find Out Whether Hardware Attack Filtering Has Been Activated; Viewing The Attack Log; The Attack Log - Cisco SCE8000 Configuration Manual

Service control engine
Table of Contents

Advertisement

Monitoring Attack Filtering

How to find out whether hardware attack filtering has been activated

From the SCE> prompt, type show interface linecard 0 attack-filter current-attacks and press Enter.
Step 1
In the output from this command, look for the "HW-filter" field. If this field is "yes", the user must take
into account the probable inaccuracies in the attack reporting.
This information also appears in the attack log file.
Note
---|---------------|-----------|------------|----------|------|------|------
---|Source IP -----|Side /
---|
---|
---|---------------|-----------|------------|----------|------|------|------
---|----------------|-----------|------------|------------|------|------|-------

Viewing the Attack Log

The Attack Log

The attack-log contains a message for each specific-IP detection of attack beginning and attack end.
Messages are in CSV format.
The message for detecting attack beginning contains the following data:
The message for detecting attack end contains the following data:
Cisco SCE8000 Software Configuration Guide, Rel 3.1.6S
10-28
Dest IP|Protocol
|Duration
|10.1.1.1
|Subscriber|
|
*|TCP
The Attack Log, page 10-28
How to View the Attack Log, page 10-29
How to Copy the Attack Log to a File, page 10-29
IP address (Pair of addresses, if detected)
Protocol Port number (If detected)
Attack-direction (Attack-source or Attack-destination)
Interface of IP address (subscriber or network)
Open-flows-rate, suspected-flows-rate and suspected-flows-ratio at the time of attack detection
Threshold values for the detection
Action taken
IP address (Pair of addresses, if detected)
Protocol Port number (If detected)
Attack-direction (Attack-source or Attack-destination)
Interface of IP address
Number of attack flows reported/blocked
Chapter 10
Identifying and Preventing Distributed-Denial-Of-Service Attacks
|Open rate / |Handled
|Susp. rate
|
flows / |
|
|
|
523|
4045|Report|No
|
0| 9|
|Action|HW-
|force-
|filter|filter
|No
|
|
OL-16479-01

Advertisement

Table of Contents
loading

Table of Contents