Download Print this page

Cisco ASA 5506-X Configuration Manual page 329

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

Chapter 15
Threat Detection
Procedure
Step 1
Configure Basic Threat Detection Statistics, page
Basic threat detection statistics include activity that might be related to an attack, such as a DoS attack.
Step 2
Configure Advanced Threat Detection Statistics, page
Step 3
Configure Scanning Threat Detection, page
Configure Basic Threat Detection Statistics
Basic threat detection statistics is enabled by default. You can disabled it, or turn it on again if you
disable it.
Procedure
Step 1
Enable basic threat detection statistics (if you previously disabled it).
threat-detection basic-threat
Example:
hostname(config)# threat-detection basic-threat
Basic threat detection is enabled by default. Use no threat-detection basic-threat to disable it.
(Optional) Change the default settings for one or more type of event.
Step 2
threat-detection rate {acl-drop | bad-packet-drop | conn-limit-drop | dos-drop |
fw-drop | icmp-drop | inspect-drop | interface-drop | scanning-threat | syn-attack}
rate-interval rate_interval average-rate av_rate burst-rate burst_rate
Example:
hostname(config)# threat-detection rate dos-drop rate-interval 600 average-rate 60
burst-rate 100
For a description of each event type, see
When you use this command with the scanning-threat keyword, it is also used in the scanning threat
detection. If you do not configure basic threat detection, you can still use this command with the
scanning-threat keyword to configure the rate limits for scanning threat detection.
You can configure up to three different rate intervals for each event type.
Configure Advanced Threat Detection Statistics
You can configure the ASA to collect extensive statistics. By default, statistics for ACLs are enabled. To
enable other statistics, perform the following steps.
15-5.
15-5.
15-7.
Basic Threat Detection Statistics, page
Cisco ASA Series Firewall CLI Configuration Guide
Configure Threat Detection
15-2.
15-5

Hide quick links:

Advertisement

loading