Cisco SCE8000 Configuration Manual page 214

Service control engine
Table of Contents

Advertisement

Monitoring Attack Filtering
From the SCE> prompt, type show interface linecard 0 attack-filter query ((single-sided ip
Step 1
ip-address)|(dual-sided source-IP source-ip-address destination-IP dest-ip-address)) [dest-port
portnumber] configured and press Enter.
Examples
Example 1
This example shows a query for a single IP address.
SCE#>show interface linecard 0 attack-filter query single-sided ip 10.1.1.1 configured
Protocol|Side|Dir.|Action|
--------|----|----|------|----------|----------|-----|----- |------|-----|-----
TCP
TCP
TCP
TCP
UDP
UDP
UDP
UDP
ICMP
ICMP
ICMP
|
ICMP
other
other
other
other
(N) below a value means that the value is set through attack-detector #N.
SCE#>
Example 2
This example shows a query for a single IP address, with a specified port.
SCE#>show interface linecard 0 attack-filter query single-sided ip 10.1.1.1 dest-port 21
configured
Protocol|Side|Dir.|Action|
--------|----|----|------|----------|----------|-----|----- |------|-----|-----
TCP+port|net.|src.|Block |
|
TCP+port|net.|dst.|Report|
TCP+port|sub.|src.|Block |
|
TCP+port|sub.|dst.|Report|
UDP+port|net.|src.|Report|
UDP+port|net.|dst.|Report|
UDP+port|sub.|src.|Report|
UDP+port|sub.|dst.|Report|
(N) below a value means that the value is set through attack-detector #N.
SCE#>
Cisco SCE8000 Software Configuration Guide, Rel 3.1.6S
10-26
|
|
|
|Open flows|Ddos-Susp. flows|filter|filter|notif|
|
|
|
|rate
|net.|src.|Report|
|net.|dst.|Report|
|sub.|src.|Report|
|sub.|dst.|Report|
|net.|src.|Report|
|net.|dst.|Report|
|sub.|src.|Report|
|sub.|dst.|Report|
|net.|src.|Report|
|net.|dst.|Report|
|sub.|src.|Report|
|
|
|
|sub.|dst.|Report|
|net.|src.|Report|
|net.|dst.|Report|
|sub.|src.|Report|
|sub.|dst.|Report|
|
|
|
|Open flows|Ddos-Susp. flows|filter|filter|notif|
|
|
|
|rate
|
|(1)
|
|
|(1)
|
Chapter 10
Identifying and Preventing Distributed-Denial-Of-Service Attacks
Thresholds
|rate
|ratio|
1000|
500|
1000|
500|
1000|
500|
1000|
500|
1000|
500|
1000|
500|
1000|
500|
1000|
500|
500|
250|
500|
250|
500|
250|
|
|
|
500|
250|
500|
250|
500|
250|
500|
250|
500|
250|
Thresholds
|rate
|ratio|
1000|
500|
|
|
|
1000|
500|
1000|
500|
|
|
|
1000|
500|
1000|
500|
1000|
500|
1000|
500|
1000|
500|
|don't- |force-|Sub- |Alarm
|
|
|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
Yes|
|
|
(1)|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
|don't- |force-|Sub- |Alarm
|
|
|
50|No
|No
|
No|
|
|
|
(1)
50|No
|No
|
No|
50|No
|No
|
No|
|
|
|
(1)
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
50|No
|No
|
No|
No
No
No
No
No
No
No
No
No
No
No
No
No
No
No
No
Yes
No
Yes
No
No
No
No
No
OL-16479-01

Advertisement

Table of Contents
loading

Table of Contents