23-7
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 23 Preventing Network Attacks
Configuring Threat Detection
The following is sample output from the
show threat-detection shun
command:
hostname#
show threat-detection shun
Shunned Host List:
10.1.1.6
198.1.6.7
Viewing Attackers and Targets
To view the hosts that the security appliance decides are attackers (including hosts on the shun list), and
to view the hosts that are the target of an attack, enter the following command:
hostname#
show threat-detection scanning-threat
[
attacker
|
target
]
If you do not enter an option, both attackers and target hosts are displayed.
The following is sample output from the
show threat-detection scanning-threat attacker
command:
hostname#
show threat-detection scanning-threat attacker
10.1.2.3
10.8.3.6
209.165.200.225
Configuring and Viewing Threat Statistics
You can configure the security appliance to collect extensive statistics. Threat detection statistics show
both allowed and dropped traffic rates. To view statistics for basic threat detection, see the
“Managing
Basic Threat Statistics” section on page 23-4
. By default, statistics for access lists are enabled.
Caution
Enabling statistics can affect the security appliance performance, depending on the type of statistics
enabled. The
threat-detection statistics host
command affects performance in a significant way; if you
have a high traffic load, you might consider enabling this type of statistics temporarily. The
threat-detection statistics port
command, however, has modest impact.
This section includes the following topics:
•
Configuring Threat Statistics, page 23-7
•
Viewing Threat Statistics, page 23-8
Configuring Threat Statistics
By default, statistics for access lists are enabled. To enable
all
statistics, enter the following command:
hostname(config)#
threat-detection statistics
To enable only certain statistics, enter one or more of the following commands.
•
To enable statistics for access lists (if they were disabled previously), enter the following command:
hostname(config)#
threat-detection statistics access-list
Access list statistics are only displayed using the
show threat-detection top access-list
command.
•
To enable statistics for hosts, enter the following command:
hostname(config)#
threat-detection statistics host
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......