AudioCodes Mediant 800B User Manual page 153

Analog & digital voip media gateway
Hide thumbs Also See for Mediant 800B:
Table of Contents

Advertisement

User's Manual
be at least twice the 'Threshold Window' value (configured in ''Configuring IDS
Policies'' on page 147). For example, if you set IDSAlarmClearPeriod to 20 sec
and 'Threshold Window' to 15 sec, the IDSAlarmClearPeriod parameter is
ignored and the alarm is cleared only after 30 seconds (2 x 15 sec).
The figure below displays an example of IDS alarms in the Active Alarms table
(''Viewing Active Alarms'' on page 627). In this example, a Minor threshold alarm
is cleared and replaced by a Major threshold alarm:
acIDSBlacklistNotification event: The device sends this event whenever an attacker
(remote host at IP address and/or port) is added to or removed from the blacklist.
You can also view IDS alarms in the CLI, using the following commands:
To view all active IDS alarms:
show voip security ids active-alarm all
To view all IP addresses that crossed the threshold for an active IDS alarm:
show voip security ids active-alarm match * rule *
To view the blacklist:
# show voip security ids blacklist active
For example:
Active blacklist entries:
10.33.5.110(NI:0) remaining 00h:00m:10s in blacklist
Where SI is the SIP Interface and NI is the network interface.
The device also sends IDS notifications in Syslog messages to a Syslog server. This only
occurs if you have configured Syslog (see ''Enabling Syslog'' on page 673). The table
below shows the Syslog text message per malicious event:
Table 13-6: Types of Malicious Events and Syslog Text String
Type
Connection
TLS authentication failure
Abuse
Malformed
Messages
Authentication
Failure
Dialog
Version 6.8
Figure 13-8: IDS Alarms in Active Alarms Table
Description
Message exceeds a user-defined maximum
message length (50K)
Any SIP parser error
Message policy match
Basic headers not present
Content length header not present (for TCP)
Header overflow
Local authentication ("Bad digest" errors)
Remote authentication (SIP 401/407 is sent if
original message includes authentication)
Classification failure
153
Mediant 800B Gateway and E-SBC
13. Security
Syslog String
abuse-tls-auth-fail
malformed-invalid-
msg-len
malformed-parse-error
malformed-message-
policy
malformed-miss-
header
malformed-miss-
content-len
malformed-header-
overflow
auth-establish-fail
auth-reject-response
establish-classify-fail

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents