Cisco ASA Series Cli Configuration Manual page 1432

Software version 9.0 for the services module
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Configuring Basic Threat Detection Statistics
Table 1-1
Packet Drop Reason
Denial by access lists
Interface overload
Configuring Basic Threat Detection Statistics
This section describes how to configure basic threat detection statistics, including enabling or disabling
it and changing the default limits.
Detailed Steps
Command
Step 1
threat-detection basic-threat
Example:
hostname(config)# threat-detection
basic-threat
Step 2
threat-detection rate {acl-drop |
bad-packet-drop | conn-limit-drop |
dos-drop | fw-drop | icmp-drop |
inspect-drop | interface-drop |
scanning-threat | syn-attack}
rate-interval rate_interval average-rate
av_rate burst-rate burst_rate
Example:
hostname(config)# threat-detection rate
dos-drop rate-interval 600 average-rate 60
burst-rate 100
Cisco ASA Series CLI Configuration Guide
1-4
Basic Threat Detection Default Settings (continued)
Basic firewall checks failed
Packets failed application
inspection
Trigger Settings
Average Rate
400 drops/sec over the last 600
seconds.
320 drops/sec over the last
3600 seconds.
400 drops/sec over the last 600
seconds.
320 drops/sec over the last
3600 seconds.
2000 drops/sec over the last
600 seconds.
1600 drops/sec over the last
3600 seconds.
Purpose
Enables basic threat detection statistics (if you previously
disabled it). Basic threat detection is enabled by default.
(Optional) Changes the default settings for one or more type of
event.
For a description of each event type, see the
Basic Threat Detection Statistics" section on page
When you use this command with the scanning-threat keyword,
it is also used in the scanning threat detection feature (see the
"Configuring Scanning Threat Detection"
configure basic threat detection, you can still use this command
with the scanning-threat keyword to configure the rate limits for
scanning threat detection.
You can configure up to three different rate intervals for each
event type.
Chapter 1
Configuring Threat Detection
Burst Rate
800 drops/sec over the last 20
second period.
640 drops/sec over the last 120
second period.
1600 drops/sec over the last 20
second period.
1280 drops/sec over the last 120
second period.
8000 drops/sec over the last 20
second period.
6400 drops/sec over the last 120
second period.
"Information About
1-2.
section). If you do not

Advertisement

Table of Contents
loading

Table of Contents