Defaults For Threat Detection; Configure Threat Detection - Cisco ASA Series Configuration Manual

Firewall cli, asa services module, and the adaptive security virtual appliance
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Defaults for Threat Detection

Defaults for Threat Detection
Basic threat detection statistics are enabled by default.
The following table lists the default settings. You can view all these default settings using the show
running-config all threat-detection command.
For advanced statistics, by default, statistics for ACLs are enabled.
Table 18-2
Packet Drop Reason
Scanning attack detected
Incomplete session detected such as
TCP SYN attack detected or UDP
session with no return data attack
detected (combined)
Denial by ACLs
Interface overload

Configure Threat Detection

Basic threat detection statistics are enabled by default, and might be the only threat detection service that
you need. Use the following procedure if you want to implement additional threat detection services.
Cisco ASA Series Firewall CLI Configuration Guide
18-4
Basic Threat Detection Default Settings
DoS attack detected
Bad packet format
Connection limits exceeded
Suspicious ICMP packets
detected
Basic firewall checks failed
Packets failed application
inspection
Trigger Settings
Average Rate
100 drops/sec over the last 600
seconds.
80 drops/sec over the last 3600
seconds.
5 drops/sec over the last 600
seconds.
4 drops/sec over the last 3600
seconds.
100 drops/sec over the last 600
seconds.
80 drops/sec over the last 3600
seconds.
400 drops/sec over the last 600
seconds.
320 drops/sec over the last
3600 seconds.
400 drops/sec over the last 600
seconds.
320 drops/sec over the last
3600 seconds.
2000 drops/sec over the last
600 seconds.
1600 drops/sec over the last
3600 seconds.
Chapter 18
Threat Detection
Burst Rate
400 drops/sec over the last 20
second period.
320 drops/sec over the last 120
second period.
10 drops/sec over the last 20
second period.
8 drops/sec over the last 120
second period.
200 drops/sec over the last 20
second period.
160 drops/sec over the last 120
second period.
800 drops/sec over the last 20
second period.
640 drops/sec over the last 120
second period.
1600 drops/sec over the last 20
second period.
1280 drops/sec over the last 120
second period.
8000 drops/sec over the last 20
second period.
6400 drops/sec over the last 120
second period.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents