Preventing Attack Filtering; How To Configure A Dont-Filter Setting For A Specified Situation; How To Remove A Dont-Filter Setting From A Specified Situation; How To Remove All Dont-Filter Settings - Cisco SCE8000 Configuration Manual

Service control engine
Table of Contents

Advertisement

Chapter 10
Identifying and Preventing Distributed-Denial-Of-Service Attacks

Preventing Attack Filtering

Attack filtering can be prevented for a specified IP address and attack type by executing a dont-filter CLI
command. If filtering is already in process, it will be stopped. When attack filtering has been stopped, it
remains stopped until explicitly restored by another CLI command (either force-filter or no dont-filter).

How to Configure a dont-filter Setting for a Specified Situation

From the SCE(config if)# prompt, type attack-filter dont-filter protocol (((TCP|UDP) [dest-port
Step 1
(port-number |not-specific))|ICMP|other) attack-direction
(((single-side-source|single-side-destination|single-side-both) (ip ip-address)|(dual-sided source-ip
source-ip-address destination-ip dest-ip-address)) side (subscriber|network|both) and press Enter.

How to Remove a dont-filter Setting from a Specified Situation

Step 1
From the SCE(config if)# prompt, type no attack-filter dont-filter protocol (((TCP|UDP) [dest-port
(port-number |not-specific))|ICMP|other) attack-direction
(((single-side-source|single-side-destination|single-side-both) (ip ip-address)|(dual-sided source-ip
source-ip-address destination-ip dest-ip-address)) side (subscriber|network|both) and press Enter.

How to Remove All dont-filter Settings

From the SCE(config if)# prompt, type no attack-filter dont-filter all and press Enter.
Step 1
Forcing Attack Filtering
Attack filtering can be forced for a specified IP address/protocol. If filtering is already in process, it will
be stopped. Forced attack filtering will continue until undone by an explicit CLI command (either no
force-filter or dont-filter).
OL-16479-01
How to Configure a dont-filter Setting for a Specified Situation, page 10-19
How to Remove a dont-filter Setting from a Specified Situation, page 10-19
How to Remove All dont-filter Settings, page 10-19
How to Configure a force-filter Setting for a Specified Situation, page 10-20
How to Remove a force-filter Setting from a Specified Situation, page 10-20
How to Remove All force-filter Settings, page 10-20
Preventing and Forcing Attack Detection
Cisco SCE8000 Software Configuration Guide, Rel 3.1.6S
10-19

Advertisement

Table of Contents
loading

Table of Contents