User's Manual
162
Document #: LTRT-89729
Mediant 3000
12.4.4 Viewing IDS Alarms
The device uses SNMP (and Syslog) to notify the detection of malicious attacks. The trap
displays the IDS Policy and Rule, and the Policy-Match index.
The device sends the SNMP alarm, acIDSPolicyAlarm whenever a threshold of a specific
IDS Policy rule is crossed. For each scope that crosses this threshold, the device sends an
additional SNMP event (trap) - acIDSThresholdCrossNotification - indicating the specific
details (IP address or IP address:port). If the trap severity level is raised, the alarm of the
former severity is cleared and the device then sends a new alarm with the new severity.
The SNMP alarm is cleared after a user-defined period (configured by the ini file
parameter, IDSAlarmClearPeriod) during which no thresholds have been crossed.
However, this "quiet" period must be at least twice the Threshold Window value (configured
in 'Configuring IDS Policies' on page
). For example, if IDSAlarmClearPeriod is set to
20 sec and the Threshold Window is set to 15 sec, the IDSAlarmClearPeriod parameter is
ignored and the alarm is cleared only after 30 seconds (2 x 15 sec).
The figure below shows an example of IDS alarms in the Active Alarms table (Viewing
Active Alarms), where a minor threshold alarm is cleared and replaced by a major
threshold alarm:
Figure
12-12: IDS Alarms in Active Alarms Table
You can also view the IDS alarms in the CLI:
To view active IDS alarms:
show voip security ids active-alarm all
To view all IP addresses that crossed the threshold for an active IDS alarm:
show voip security ids active-alarm match * rule *
The device also sends IDS notifications in Syslog messages to a Syslog server (if enabled
- see Configuring Syslog). The table below shows the Syslog text message per malicious
event:
Table
12-4: Types of Malicious Events and Syslog Text String
Type
Description
Syslog String
Connection
Abuse
TLS authentication failure
abuse-tls-auth-fail
Malformed
Messages
Message exceeds a user-defined maximum
message length (50K)
Any SIP parser error
Message policy match
Basic headers not present
Content length header not present (for TCP)
Header overflow
malformed-invalid-
msg-len
malformed-parse-error
malformed-message-
policy
malformed-miss-
header
malformed-miss-
content-len
malformed-header-
overflow
Authentication
Failure
Local authentication ("Bad digest" errors)
Remote authentication (SIP 401/407 is sent if
original message includes authentication)
auth-establish-fail
auth-reject-response
Summary of Contents for Mediant 3000
Page 2: ......
Page 26: ...User s Manual 26 Document LTRT 89729 Mediant 3000 Reader s Note...
Page 27: ...Part I Getting Started with Initial Connectivity...
Page 28: ......
Page 40: ...User s Manual 40 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 41: ...Part II Management Tools...
Page 42: ......
Page 44: ...User s Manual 44 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 80: ...User s Manual 80 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 98: ...User s Manual 98 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 103: ...Part III General System Settings...
Page 104: ......
Page 113: ...Part IV General VoIP Configuration...
Page 114: ......
Page 144: ...User s Manual 144 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 164: ...User s Manual 164 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 222: ...User s Manual 222 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 224: ...User s Manual 224 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 275: ...Part V Gateway and IP to IP Application...
Page 276: ......
Page 278: ...User s Manual 278 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 399: ...Part VI Session Border Controller Application...
Page 400: ......
Page 402: ...User s Manual 402 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 464: ...User s Manual 464 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 465: ...Part VII Stand Alone Survivability Application...
Page 466: ......
Page 474: ...User s Manual 474 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 494: ...User s Manual 494 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 497: ...Part VIII IP Media Capabilities...
Page 498: ......
Page 501: ...Part IX High Availability System...
Page 502: ......
Page 515: ...Part X Maintenance...
Page 516: ......
Page 522: ...User s Manual 522 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 524: ...User s Manual 524 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 552: ...User s Manual 552 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 562: ...User s Manual 562 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 565: ...Part XI Status Performance Monitoring and Reporting...
Page 566: ......
Page 578: ...User s Manual 578 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 609: ...Part XII Diagnostics...
Page 610: ......
Page 624: ...User s Manual 624 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 626: ...User s Manual 626 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 638: ...User s Manual 638 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 639: ...Part XIII Appendix...
Page 640: ......
Page 864: ...User s Manual 864 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 871: ...Version 6 6 871 Mediant 3000 User s Manual 55 Selected Technical Specifications Reader s Notes...