How To Display The Default Attack Detector Configuration - Cisco SCE2020-4XGBE-SM Configuration Manual

Software configuration guide
Table of Contents

Advertisement

Chapter 11
Identifying and Preventing Distributed-Denial-Of-Service Attacks
UDP
UDP
UDP+port|net.|source-only||
UDP+port|net.|dest-only
UDP+port|sub.|source-only||
UDP+port|sub.|dest-only
UDP+port|net.|source+dest||
UDP+port|sub.|source+dest||
ICMP
ICMP
ICMP
ICMP
other
other
other
other
Empty fields indicate that no value is set and configuration from
the default attack detector is used.
SCE#>

How to display the default attack detector configuration

Step 1
From the SCE> prompt, type show interface linecard 0 attack-detector default and press Enter.
Example
SCE>show interface LineCard 0 attack-detector default
Default detector:
Protocol|Side|Direction
|
|
--------|----|-----------||------|----------|------------|-------|-----|-----
TCP
TCP
TCP
TCP
TCP
TCP
TCP+port|net.|source-only||Report|
TCP+port|net.|dest-only
TCP+port|sub.|source-only||Report|
TCP+port|sub.|dest-only
TCP+port|net.|source+dest||Report|
TCP+port|sub.|source+dest||Report|
UDP
UDP
UDP
UDP
UDP
UDP
UDP+port|net.|source-only||Report|
UDP+port|net.|dest-only
UDP+port|sub.|source-only||Report|
UDP+port|sub.|dest-only
UDP+port|net.|source+dest||Report|
UDP+port|sub.|source+dest||Report|
ICMP
ICMP
ICMP
ICMP
OL-7827-12
|net.|source+dest||
|sub.|source+dest||
||
||
|net.|source-only||
|net.|dest-only
||
|sub.|source-only||
|sub.|dest-only
||
|net.|source-only||
|net.|dest-only
||
|sub.|source-only||
|sub.|dest-only
||
||Action|
|
||
|Open flows|Ddos-Suspected flows|notif|
|
||
|rate
|net.|source-only||Report|
|net.|dest-only
||Report|
|sub.|source-only||Report|
|sub.|dest-only
||Report|
|net.|source+dest||Report|
|sub.|source+dest||Report|
||Report|
||Report|
|net.|source-only||Report|
|net.|dest-only
||Report|
|sub.|source-only||Report|
|sub.|dest-only
||Report|
|net.|source+dest||Report|
|sub.|source+dest||Report|
||Report|
||Report|
|net.|source-only||Report|
|net.|dest-only
||Report|
|sub.|source-only||Report|
|sub.|dest-only
||Report|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Thresholds
|rate
|ratio
1000|
500|50
1000|
500|50
1000|
500|50
1000|
500|50
100|
50|50
100|
50|50
1000|
500|50
1000|
500|50
1000|
500|50
1000|
500|50
100|
50|50
100|
50|50
1000|
500|50
1000|
500|50
1000|
500|50
1000|
500|50
100|
50|50
100|
50|50
1000|
500|50
1000|
500|50
1000|
500|50
1000|
500|50
100|
50|50
100|
50|50
500|
250|50
500|
250|50
500|
250|50
500|
250|50
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
Monitoring Attack Filtering
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|Yes
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|Sub- |Alarm
|
|
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
|No
11-25

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sce 2000Sce 1000

Table of Contents