Configuring Subscriber Notifications
Configuring Subscriber Notifications
•
•
Subscriber notification is a capability used- for notifying a subscriber in real-time about current attacks
involving IP addresses mapped to that subscriber. Subscriber notification is configured on a
per-attack-detector level, as explained above, and must also be enabled and configured by the application
loaded to the SCE platform, as explained in the appropriate Service Control Application user guide.
In the current solutions, the SCE Platform notifies the subscriber about the attack by redirecting HTTP
flows originating from the subscriber to the service provider's server, that should notify the subscriber
that he is under attack. This raises a question regarding TCP attacks originating from the subscriber that
are configured with block action. Such attacks cannot normally be notified to the subscriber using HTTP
redirection, since all HTTP flows originating from the subscriber are TCP flows, and they are therefore
blocked along with all other attack flows. To enable effective use of HTTP redirect, there is a CLI
command that prevents blocking of TCP flows originating from the subscriber to a specified TCP port,
even when the above scenario occurs.
How to Configure the Subscriber Notification Port
You can define a port to be used as the subscriber notification port. The attack filter will never block TCP
traffic from the subscriber side of the SCE platform to this port, leaving it always available for subscriber
notification.
Options
The following option is available:
•
Step 1
From the SCE(config if)# prompt, type attack-filter subscriber-notification ports portnumber and
press Enter.
How to Remove the Subscriber Notification Port
Step 1
From the SCE(config if)# prompt, type no attack-filter subscriber-notification ports and press Enter.
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
11-18
How to Configure the Subscriber Notification Port, page 11-18
How to Remove the Subscriber Notification Port, page 11-18
portnumber — the number of the port to be used as the subscriber notification port
Chapter 11
Identifying and Preventing Distributed-Denial-Of-Service Attacks
OL-7827-12
Need help?
Do you have a question about the SCE2020-4XGBE-SM and is the answer not in the manual?