User's Manual
162
Document #: LTRT-89729
Mediant 3000
12.4.4 Viewing IDS Alarms
The device uses SNMP (and Syslog) to notify the detection of malicious attacks. The trap
displays the IDS Policy and Rule, and the Policy-Match index.
The device sends the SNMP alarm, acIDSPolicyAlarm whenever a threshold of a specific
IDS Policy rule is crossed. For each scope that crosses this threshold, the device sends an
additional SNMP event (trap) - acIDSThresholdCrossNotification - indicating the specific
details (IP address or IP address:port). If the trap severity level is raised, the alarm of the
former severity is cleared and the device then sends a new alarm with the new severity.
The SNMP alarm is cleared after a user-defined period (configured by the ini file
parameter, IDSAlarmClearPeriod) during which no thresholds have been crossed.
However, this "quiet" period must be at least twice the Threshold Window value (configured
in 'Configuring IDS Policies' on page
). For example, if IDSAlarmClearPeriod is set to
20 sec and the Threshold Window is set to 15 sec, the IDSAlarmClearPeriod parameter is
ignored and the alarm is cleared only after 30 seconds (2 x 15 sec).
The figure below shows an example of IDS alarms in the Active Alarms table (Viewing
Active Alarms), where a minor threshold alarm is cleared and replaced by a major
threshold alarm:
Figure
12-12: IDS Alarms in Active Alarms Table
You can also view the IDS alarms in the CLI:
To view active IDS alarms:
show voip security ids active-alarm all
To view all IP addresses that crossed the threshold for an active IDS alarm:
show voip security ids active-alarm match * rule *
The device also sends IDS notifications in Syslog messages to a Syslog server (if enabled
- see Configuring Syslog). The table below shows the Syslog text message per malicious
event:
Table
12-4: Types of Malicious Events and Syslog Text String
Type
Description
Syslog String
Connection
Abuse
TLS authentication failure
abuse-tls-auth-fail
Malformed
Messages
Message exceeds a user-defined maximum
message length (50K)
Any SIP parser error
Message policy match
Basic headers not present
Content length header not present (for TCP)
Header overflow
malformed-invalid-
msg-len
malformed-parse-error
malformed-message-
policy
malformed-miss-
header
malformed-miss-
content-len
malformed-header-
overflow
Authentication
Failure
Local authentication ("Bad digest" errors)
Remote authentication (SIP 401/407 is sent if
original message includes authentication)
auth-establish-fail
auth-reject-response
Содержание Mediant 3000
Страница 1: ...User s Manual Version 6 6 Enterprise Session Border Controller VoIP Digital Media Gateway Mediant 3000...
Страница 2: ......
Страница 21: ...Version 6 6 21 Mediant 3000 User s Manual 1 Overview Figure 1 2 Mediant 3000 TP 6310 Functional Block Diagram...
Страница 22: ...User s Manual 22 Document LTRT 89729 Mediant 3000 Figure 1 3 Mediant 3000 TP 8410 Functional Block Diagram...
Страница 26: ...User s Manual 26 Document LTRT 89729 Mediant 3000 Reader s Note...
Страница 27: ...Part I Getting Started with Initial Connectivity...
Страница 28: ......
Страница 40: ...User s Manual 40 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 41: ...Part II Management Tools...
Страница 42: ......
Страница 44: ...User s Manual 44 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 80: ...User s Manual 80 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 98: ...User s Manual 98 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 103: ...Part III General System Settings...
Страница 104: ......
Страница 113: ...Part IV General VoIP Configuration...
Страница 114: ......
Страница 144: ...User s Manual 144 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 164: ...User s Manual 164 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 222: ...User s Manual 222 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 224: ...User s Manual 224 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 275: ...Part V Gateway and IP to IP Application...
Страница 276: ......
Страница 278: ...User s Manual 278 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 399: ...Part VI Session Border Controller Application...
Страница 400: ......
Страница 402: ...User s Manual 402 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 464: ...User s Manual 464 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 465: ...Part VII Stand Alone Survivability Application...
Страница 466: ......
Страница 474: ...User s Manual 474 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 494: ...User s Manual 494 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 497: ...Part VIII IP Media Capabilities...
Страница 498: ......
Страница 501: ...Part IX High Availability System...
Страница 502: ......
Страница 515: ...Part X Maintenance...
Страница 516: ......
Страница 522: ...User s Manual 522 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 524: ...User s Manual 524 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 552: ...User s Manual 552 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 562: ...User s Manual 562 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 565: ...Part XI Status Performance Monitoring and Reporting...
Страница 566: ......
Страница 578: ...User s Manual 578 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 609: ...Part XII Diagnostics...
Страница 610: ......
Страница 624: ...User s Manual 624 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 626: ...User s Manual 626 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 638: ...User s Manual 638 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 639: ...Part XIII Appendix...
Страница 640: ......
Страница 864: ...User s Manual 864 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 871: ...Version 6 6 871 Mediant 3000 User s Manual 55 Selected Technical Specifications Reader s Notes...
Страница 872: ...User s Manual Ver 6 6 www audiocodes com...