How The Intrusion Log Operates - HP E3800-24G-PoE+-2SFP+ Access Security Manual

Switch software
Hide thumbs Also See for E3800-24G-PoE+-2SFP+:
Table of Contents

Advertisement

Note on
Send-Disable
Operation

How the Intrusion Log Operates

When the switch detects an intrusion attempt on a port, it enters a record of
this event in the Intrusion Log. No further intrusion attempts on that port will
appear in the Log until you acknowledge the earlier intrusion event by reset-
ting the alert flag.
The Intrusion Log lists the 20 most recently detected security violation
attempts, regardless of whether the alert flags for these attempts have been
reset. This gives you a history of past intrusion attempts. Thus, for example,
if there is an intrusion alert for port A and the Intrusion Log shows two or
more entries for port 1, only the most recent entry has not been acknowledged
(by resetting the alert flag). The other entries give you a history of past
intrusions detected on port A.
Status and Counters - Intrusion Log
Port
MAC Address
---- ------------- ---------------------------
108009-e93d4f
09/07/2011 21:09:34
208009-e93d4f
09/07/2011 10:18:43
Figure 14-14. Example of Multiple Intrusion Log Entries for the Same Port
The log shows the most recent intrusion at the top of the listing. You cannot
delete Intrusion Log entries (unless you reset the switch to its factory-default
configuration). Instead, if the log is filled when the switch detects a new
intrusion, the oldest entry is dropped off the listing and the newest entry
appears at the top of the listing.
Keeping the Intrusion Log Current by Resetting Alert
Flags
When a violation occurs on a port, an alert flag is set for that port and the
violation is entered in the Intrusion Log. The switch can detect and handle
subsequent intrusions on that port, but will not log another intrusion on the
port until you reset the alert flag for either all ports or for the individual port.
On a given port, if the intrusion action is to send an SNMP trap and then disable
the port (send-disable), and an intruder is detected on the port, then the switch
sends an SNMP trap, sets the port's alert flag, and disables the port. If you re-
enable the port without resetting the port's alert flag, then the port operates
as follows:
Configuring and Monitoring Port Security
Reading Intrusion Alerts and Resetting Alert Flags
Date / Time
14-35

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents