Performance Monitoring and Alarms
154
Document #: LTRT-32111
Mediant 3000 with TP-6310
3.4.7
IDS Blacklist Notification
IDS Blacklist Notification
Description
This alarm notifies when an IP address has been added or removed
from a blacklist.
SNMP Alarm
acIDSBlacklistNotification
SNMP OID
1.3.6.1.4.1.5003.9.10.1.21.2.0.101
Default Severity
Alarm Type
securityServiceOrMechanismViolation
Probable Cause
thresholdCrossed
Alarm Text
Added IP * to blacklist
Removed IP * from blacklist
Status Changes
Corrective Action
Identify the malicious remote host (IP address / port) that the Intrusion
Detection System (IDS) has automatically blacklisted or removed from
the blacklist.
Note that a host is determined to be malicious if it has reached or
exceeded a user-defined threshold of malicious attacks (counter). The
malicious source is automatically blacklisted for a user-defined period,
after which it is removed from the blacklist.
Содержание Mediant 3000 TP-6310
Страница 2: ......
Страница 10: ......
Страница 11: ...Version 7 0 11 OAM Guide Performance Monitoring and Alarms 1 Introduction This page is intentionally left blank...
Страница 12: ......
Страница 116: ...Performance Monitoring and Alarms 116 Document LTRT 32111 Mediant 3000 with TP 6310 Cleared HA system is active...