How To Define The Default Action And Optionally, The Default Thresholds - Cisco SCE 8000 10GBE Software Configuration Manual

Table of Contents

Advertisement

Chapter 12
Identifying and Preventing Distributed Denial-of-Service Attacks

How to Define the Default Action and Optionally, the Default Thresholds

Defaults
The default values for the default attack detector are:
Step 1
From the SCE(config if)# prompt, type
(specific|not- specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all) side
(subscriber|network|both) [action (report|block)] [open-flows-rate number suspected-flows-rate
rate suspected-flows-ratio ratio
Configures the default attack detector for the defined attack type.
From the SCE(config if)# prompt, type attack-detector default protocol (((TCP|UDP) [dest-port
Step 2
(specific|not- specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all) side
(subscriber|network|both) (notify-subscriber|don't-notify-subscriber) and press Enter.
Enables or disables subscriber notification by default for the defined attack type.
The attack type must be defined the same as in Step 1.
Step 3
From the SCE(config if)# prompt, type attack-detector default protocol (((TCP|UDP) [dest-port
(specific|not- specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all) side
(subscriber|network|both) (alarm|no-alarm) and press Enter.
Enables or disables sending an SNMP trap by default for the defined attack type.
The attack type must be defined the same as in Step 1.
How to Reinstate the System Defaults for a Selected Set of Attack Types
Use the following command to delete user-defined default values for action, thresholds, subscriber
notification, and sending an SNMP trap for a selected set of attack types, and reinstate the system
defaults.
From the SCE(config if)# prompt, type:
Command
default attack-detector default protocol
(((TCP|UDP) [dest-port (specific|not-
specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-si
de-both|dual-sided|all) side
(subscriber|network|both)
OL-30621-02
Action—Report
Thresholds—Varies according to the attack type
Subscriber notification—Disabled
Sending an SNMP trap—Disabled
ttack-detector default protocol (((TCP|UDP) [dest-port
a
and press Enter.
]
Purpose
Reinstates the system defaults for the defined
attack types.
Cisco SCE 8000 10GBE Software Configuration Guide
Configuring Attack Detectors
12-13

Advertisement

Table of Contents
loading

Table of Contents