23-9
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 23 Preventing Network Attacks
Configuring Threat Detection
The
rate-1
keyword shows the statistics for the smallest fixed rate intervals available in the display;
rate-2
shows the next largest rate interval; and
rate-3
, if you have three intervals defined,
shows the
largest rate interval. For example, the display shows statistics for the last 1 hour, 8 hours, and 24
hours. If you set the
rate-1
keyword, the security appliance shows only the 1 hour time interval.
•
To view statistics for all hosts or for a specific host or subnet, enter the following command:
hostname#
show
threat-detection statistics
[
min-display-rate
min_display_rate
]
host
[
ip_address
[
mask
]]
•
To view statistics for all ports or for a specific port or range of ports, enter the following command:
hostname#
show
threat-detection statistics
[
min-display-rate
min_display_rate
]
port
[
start_port
[
-
end_port
]]
•
To view statistics for all IP protocols or for a specific protocol, enter the following command:
hostname#
show
threat-detection statistics
[
min-display-rate
min_display_rate
]
protocol
[
protocol_number
|
ah
|
eigrp
|
esp
|
gre
|
icmp
|
igmp
|
igrp
|
ip
|
ipinip
|
ipsec
|
nos
|
ospf
|
pcp
|
pim
|
pptp
|
snp
|
tcp
|
udp
]
where the
protocol_number
argument is an integer between 0 and 255.
The following is sample output from the
show threat-detection statistics host
command:
hostname#
show threat-detection statistics host
Average(eps) Current(eps) Trigger Total events
Host:10.0.0.1: tot-ses:289235 act-ses:22571 fw-drop:0 insp-drop:0 null-ses:21438 bad-acc:0
1-hour Sent byte: 2938 0 0 10580308
8-hour Sent byte: 367 0 0 10580308
24-hour Sent byte: 122 0 0 10580308
1-hour Sent pkts: 28 0 0 104043
8-hour Sent pkts: 3 0 0 104043
24-hour Sent pkts: 1 0 0 104043
20-min Sent drop: 9 0 1 10851
1-hour Sent drop: 3 0 1 10851
1-hour Recv byte: 2697 0 0 9712670
8-hour Recv byte: 337 0 0 9712670
24-hour Recv byte: 112 0 0 9712670
1-hour Recv pkts: 29 0 0 104846
8-hour Recv pkts: 3 0 0 104846
24-hour Recv pkts: 1 0 0 104846
20-min Recv drop: 42 0 3 50567
1-hour Recv drop: 14 0 1 50567
Host:10.0.0.0: tot-ses:1 act-ses:0 fw-drop:0 insp-drop:0 null-ses:0 bad-acc:0
1-hour Sent byte: 0 0 0 614
8-hour Sent byte: 0 0 0 614
24-hour Sent byte: 0 0 0 614
1-hour Sent pkts: 0 0 0 6
8-hour Sent pkts: 0 0 0 6
24-hour Sent pkts: 0 0 0 6
20-min Sent drop: 0 0 0 4
1-hour Sent drop: 0 0 0 4
1-hour Recv byte: 0 0 0 706
8-hour Recv byte: 0 0 0 706
24-hour Recv byte: 0 0 0 706
1-hour Recv pkts: 0 0 0 7
Table 23-3
shows each field description.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......