Version 6.6
159
Mediant 3000
User's Manual
12. Security
Table
12-2: IDS Rule Table Parameters
Parameter
Description
Index
CLI: rule-id
[IDSRule_RuleID]
Defines the table row number for the rule.
Reason
CLI: reason
[IDSRule_Reason]
Defines the type of intrusion attack (malicious event).
[0]
Any = All events listed below are considered as attacks and
are counted together.
[1]
Connection abuse (default) = TLS authentication failure.
[2]
Malformed message =
Message exceeds a user-defined maximum message length
(50K)
Any SIP parser error
Message Policy match (see Configuring SIP Message Policy
Rules)
Basic headers not present
Content length header not present (for TCP)
Header overflow
[3]
Authentication failure =
Local authentication ("Bad digest" errors)
Remote authentication (SIP 401/407 is sent if original
message includes authentication)
[4]
Dialog establish failure =
Classification failure (see Configuring Classification Rules)
Routing failure
Other local rejects (prior to SIP 180 response)
Remote rejects (prior to SIP 180 response)
[5]
Abnormal flow =
Requests and responses without a matching transaction user
(except ACK requests)
Requests and responses without a matching transaction
(except ACK requests)
Threshold Scope
CLI: threshold-scope
[IDSRule_ThresholdScope
]
Defines the source of the attacker to consider in the device's
detection count.
[0]
Global = All attacks regardless of source are counted together
during the threshold window.
[2]
IP = Attacks from each specific IP address are counted
separately during the threshold window.
[3]
IP+Port = Attacks from each specific IP address:port are
counted separately during the threshold window. This option is
useful for NAT servers, where numerous remote machines use
the same IP address but different ports. However, it is not
recommended to use this option as it may degrade detection
capabilities.
Threshold Window
CLI: threshold-window
[IDSRule_ThresholdWindo
w]
Defines the threshold interval (in seconds) during which the device
counts the attacks to check if a threshold is crossed. The counter is
automatically reset at the end of the interval.
The valid range is 1 to 1,000,000. The default is 1.
Summary of Contents for Mediant 3000
Page 2: ......
Page 26: ...User s Manual 26 Document LTRT 89729 Mediant 3000 Reader s Note...
Page 27: ...Part I Getting Started with Initial Connectivity...
Page 28: ......
Page 40: ...User s Manual 40 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 41: ...Part II Management Tools...
Page 42: ......
Page 44: ...User s Manual 44 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 80: ...User s Manual 80 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 98: ...User s Manual 98 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 103: ...Part III General System Settings...
Page 104: ......
Page 113: ...Part IV General VoIP Configuration...
Page 114: ......
Page 144: ...User s Manual 144 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 164: ...User s Manual 164 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 222: ...User s Manual 222 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 224: ...User s Manual 224 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 275: ...Part V Gateway and IP to IP Application...
Page 276: ......
Page 278: ...User s Manual 278 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 399: ...Part VI Session Border Controller Application...
Page 400: ......
Page 402: ...User s Manual 402 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 464: ...User s Manual 464 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 465: ...Part VII Stand Alone Survivability Application...
Page 466: ......
Page 474: ...User s Manual 474 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 494: ...User s Manual 494 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 497: ...Part VIII IP Media Capabilities...
Page 498: ......
Page 501: ...Part IX High Availability System...
Page 502: ......
Page 515: ...Part X Maintenance...
Page 516: ......
Page 522: ...User s Manual 522 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 524: ...User s Manual 524 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 552: ...User s Manual 552 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 562: ...User s Manual 562 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 565: ...Part XI Status Performance Monitoring and Reporting...
Page 566: ......
Page 578: ...User s Manual 578 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 609: ...Part XII Diagnostics...
Page 610: ......
Page 624: ...User s Manual 624 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 626: ...User s Manual 626 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 638: ...User s Manual 638 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 639: ...Part XIII Appendix...
Page 640: ......
Page 864: ...User s Manual 864 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 871: ...Version 6 6 871 Mediant 3000 User s Manual 55 Selected Technical Specifications Reader s Notes...