User's Manual
150
Document #: LTRT-10437
Mediant 500 E-SBC
Parameter
Description
[5]
Abnormal flow =
Requests and responses without a matching
transaction user (except ACK requests)
Requests and responses without a matching
transaction (except ACK requests)
Threshold Scope
CLI: threshold-scope
[IDSRule_ThresholdScope]
Defines the source of the attacker to consider in the device's
detection count.
[0]
Global = All attacks regardless of source are counted
together during the threshold window.
[2]
IP = Attacks from each specific IP address are counted
separately during the threshold window.
[3]
IP+Port = Attacks from each specific IP address:port are
counted separately during the threshold window. This option
is useful for NAT servers, where numerous remote
machines use the same IP address but different ports.
However, it is not recommended to use this option as it may
degrade detection capabilities.
Threshold Window
CLI: threshold-window
[IDSRule_ThresholdWindow]
Defines the threshold interval (in seconds) during which the
device counts the attacks to check if a threshold is crossed.
The counter is automatically reset at the end of the interval.
The valid range is 1 to 1,000,000. The default is 1.
Minor-Alarm Threshold
CLI: minor-alrm-thr
[IDSRule_MinorAlarmThreshold]
Defines the threshold that if crossed a minor severity alarm is
sent.
The valid range is 1 to 1,000,000. A value of 0 or -1 means not
defined.
Major-Alarm Threshold
CLI: major-alrm-thr
[IDSRule_MajorAlarmThreshold]
Defines the threshold that if crossed a major severity alarm is
sent.
The valid range is 1 to 1,000,000. A value of 0 or -1 means not
defined.
Critical-Alarm Threshold
CLI: critical-alrm-thr
[IDSRule_CriticalAlarmThreshold]
Defines the threshold that if crossed a critical severity alarm is
sent.
The valid range is 1 to 1,000,000. A value of 0 or -1 means not
defined.
Deny Threshold
[IDSRule_DenyThreshold]
Defines the threshold that if crossed, the device blocks
(blacklists) the remote host (attacker).
The default is -1 (i.e., not configured).
Note:
This parameter is applicable only if the 'Threshold
Scope' parameter is set to
IP
or
IP+Port
.
Deny Period
[IDSRule_DenyPeriod]
Defines the duration (in sec) to keep the attacker on the
blacklist.
The valid range is 0 to 1,000,000. The default is -1 (i.e., not
configured).
Summary of Contents for Mediant 500 E-SBC
Page 2: ......
Page 16: ...User s Manual 16 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 22: ...User s Manual 22 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 23: ...Part I Getting Started with Initial Connectivity...
Page 24: ......
Page 26: ...User s Manual 26 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 28: ...User s Manual 28 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 33: ...Part II Management Tools...
Page 34: ......
Page 36: ...User s Manual 36 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 64: ...User s Manual 64 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 82: ...User s Manual 82 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 89: ...Part III General System Settings...
Page 90: ......
Page 106: ...User s Manual 106 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 107: ...Part IV General VoIP Configuration...
Page 108: ......
Page 238: ...User s Manual 238 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 250: ...User s Manual 250 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 280: ...User s Manual 280 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 329: ...Part V Gateway Application...
Page 330: ......
Page 332: ...User s Manual 332 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 352: ...User s Manual 352 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 412: ...User s Manual 412 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 441: ...Part VI Session Border Controller Application...
Page 442: ......
Page 489: ...User s Manual 28 SBC Configuration Version 6 8 489 Mediant 500 E SBC...
Page 510: ...User s Manual 510 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 511: ...Part VII Cloud Resilience Package...
Page 512: ......
Page 521: ...Part VIII High Availability System...
Page 522: ......
Page 536: ...User s Manual 536 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 537: ...Part IX Maintenance...
Page 538: ......
Page 544: ...User s Manual 544 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 546: ...User s Manual 546 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 548: ...User s Manual 548 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 582: ...User s Manual 582 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 600: ...User s Manual 600 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 602: ...User s Manual 602 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 603: ...Part X Status Performance Monitoring and Reporting...
Page 604: ......
Page 654: ...User s Manual 654 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 655: ...Part XI Diagnostics...
Page 656: ......
Page 672: ...User s Manual 672 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 687: ...Part XII Appendix...
Page 688: ......
Page 914: ...User s Manual 914 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...