Download Cisco SCE8000 Specifications
Transcript
Chapter 2
CLI Command Reference
attack-detector number
attack-detector number
Configures a specific attack detector for a particular attack type (protocol, attack direction, or side) with
the assigned number.
To configure the default attack detector for the specified attack type, use the default form of this
command.
To delete the specified attack detector, use the no form of this command.
attack-detector number protocol {TCP | UDP | ICMP | other | all} [destination-port
destination-port] attack-direction attack-direction side side [action action] [open-flows
open-flows] [ddos-suspected-flows ddos-suspected-flows] [suspected-flows-ratio
suspected-flows-ratio] [notify-subscriber | dont-notify-subscriber] [alarm | no-alarm]
no attack-detector number
attack-detector default protocol {TCP | UDP | ICMP | other | all} [destination-port
destination-port] attack-direction attack-direction side side [action action] [open-flows
open-flows] [ddos-suspected-flows ddos-suspected-flows] [suspected-flows-ratio
suspected-flows-ratio] [notify-subscriber | dont-notify-subscriber] [alarm | no-alarm]
no attack-detector default protocol {TCP | UDP | ICMP | other | all} [destination-port
destination-port] attack-direction attack-direction side side
default attack-detector {all | all-numbered}
default attack-detector number protocol {all | IMCP | other | TCP | UDP} [destination-port
destination-port] attack-direction attack-direction side side
Syntax Description
number
Assigned number for the attack detector.
protocol
For protocol, choose TCP, UDP, IMCP, or other.
destination port
(TCP and UDP protocols only) Defines whether the default attack detector
applies to specific (port-based) or not-specific (port-less) detections.
For destination-port, choose specific, not-specific, or both.
attack-direction
For attack-direction, choose single-side-destination, single-side-both,
dual-sided, or all.
side
For side, choose subscriber, network, or both.
action
For action, choose report or block.
open-flows-rate
Threshold for rate of open flows (new open flows per second).
suspected-flows-rate
Threshold for rate of suspected DDoS flows (new suspected flows per
second).
suspected-flows-ratio
Threshold for ratio of suspected flow rate to open flow rate.
notify-subscriber,
Enables or disables subscriber notification.
dont-notify-subscriber
alarm, noalarm
Enables or disables sending of SNMP traps.
Cisco SCE 8000 CLI Command Reference
2-25