![Cisco SCE8000 GBE Configuration Manual Download Page 199](http://html.mh-extra.com/html/cisco/sce8000-gbe/sce8000-gbe_configuration-manual_19298199.webp)
10-11
Cisco SCE8000 Software Configuration Guide, Rel 3.1.6S
OL-16479-01
Chapter 10 Identifying and Preventing Distributed-Denial-Of-Service Attacks
Configuring Attack Detectors
•
Thresholds
:
–
open-flows-rate
— Default threshold for rate of open flows. suspected-flows-rate — Default
threshold for rate of suspected DDoS flows.
–
suspected-flows-ratio
— Default threshold for ratio of suspected flow rate to open flow rate.
•
Use the appropriate keyword to enable or disable subscriber notification by default:
–
notify-subscriber
— Enable subscriber notification.
–
don't-notify-subscriber
— Disable subscriber notification.
•
Use the appropriate keyword to enable or disable sending an SNMP trap by default:
–
alarm
— Enable sending an SNMP trap.
–
no-alarm
— Disable sending an SNMP trap.
How to Define the Default Action and Optionally the Default Thresholds
Defaults
The default values for the default attack detector are:
•
Action — Report
•
Thresholds — Varies according to the attack type
•
Subscriber notification — Disabled
•
Sending an SNMP trap — Disabled
Step 1
From the SCE(config if)# prompt, type
a
ttack-detector default protocol (((TCP|UDP) [dest-port
(specific|not- specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all) side
(subscriber|network|both) [action (report|block)] [open-flows-rate
number
suspected-flows-rate
rate
suspected-flows-ratio
ratio
]
and press
Enter
.
Configures the default attack detector for the defined attack type.
Step 2
From the SCE(config if)# prompt, type
attack-detector default protocol (((TCP|UDP) [dest-port
(specific|not- specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all) side
(subscriber|network|both) (notify-subscriber|don't-notify-subscriber)
and press
Enter
.
Enables or disables subscriber notification by default for the defined attack type.
The attack type must be defined the same as in Step 1.
Step 3
From the SCE(config if)# prompt, type
attack-detector default protocol (((TCP|UDP) [dest-port
(specific|not- specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all) side
(subscriber|network|both) (alarm|no-alarm)
and press Enter.
Enables or disables sending an SNMP trap by default for the defined attack type.
The attack type must be defined the same as in Step 1.