How To Find Out Whether Hardware Attack Filtering Has Been Activated - Cisco SCE 8000 10GBE Software Configuration Manual

Table of Contents

Advertisement

Monitoring Attack Filtering

How to Find out Whether Hardware Attack Filtering has been Activated

From the SCE> prompt, type show interface linecard 0 attack-filter current-attacks and press Enter.
Step 1
In the output from this command, look for the "HW-filter" field. If this field is "yes", the user must take
into account the probable inaccuracies in the attack reporting.
Note that this information also appears in the attack log file.
---|---------------|-----------|------------|----------|------|------|------
---|Source IP -----|Side /
---|
---|
---|---------------|-----------|------------|----------|------|------|------
---|----------------|-----------|------------|------------|------|------|-------
Viewing the Attack Log
The Attack Log
The attack-log contains a message for each specific-IP detection of attack beginning and attack end.
Messages are in CSV format.
The message for detecting attack beginning contains the following data:
The message for detecting attack end contains the following data:
Cisco SCE 8000 10GBE Software Configuration Guide
12-32
Dest IP|Protocol
|Duration
|10.1.1.1
|Subscriber|
|
*|TCP
The Attack Log, page 12-32
How to View the Attack Log, page 12-33
How to Copy the Attack Log to a File, page 12-33
IP address (Pair of addresses, if detected)
Protocol Port number (If detected)
Attack-direction (Attack-source or Attack-destination)
Interface of IP address (subscriber or network)
Open-flows-rate, suspected-flows-rate and suspected-flows-ratio at the time of attack detection
Threshold values for the detection
Action taken
IP address (Pair of addresses, if detected)
Protocol Port number (If detected)
Attack-direction (Attack-source or Attack-destination)
Interface of IP address
Number of attack flows reported/blocked
Action taken
Chapter 12
Identifying and Preventing Distributed Denial-of-Service Attacks
|Open rate / |Handled
|Susp. rate
|
flows / |
|
|
|
523|
4045|Report|No
|
0| 9|
|Action|HW-
|force-
|filter|filter
|No
|
|
OL-30621-02

Advertisement

Table of Contents
loading

Table of Contents