15-5
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 15 Threat Detection
Configure Threat Detection
Procedure
Step 1
Configure Basic Threat Detection Statistics, page 15-5
Basic threat detection statistics include activity that might be related to an attack, such as a DoS attack.
Step 2
Configure Advanced Threat Detection Statistics, page 15-5
Step 3
Configure Scanning Threat Detection, page 15-7
Configure Basic Threat Detection Statistics
Basic threat detection statistics is enabled by default. You can disabled it, or turn it on again if you
disable it.
Procedure
Step 1
Enable basic threat detection statistics (if you previously disabled it).
threat-detection basic-threat
Example:
hostname(config)# threat-detection basic-threat
Basic threat detection is enabled by default. Use
no threat-detection basic-threat
to disable it.
Step 2
(Optional) Change the default settings for one or more type of event.
threat-detection rate
{
acl-drop
|
bad-packet-drop
|
conn-limit-drop
|
dos-drop
|
fw-drop
|
icmp-drop
|
inspect-drop
|
interface-drop
|
scanning-threat
|
syn-attack
}
rate-interval
rate_interval
average-rate
av_rate
burst-rate
burst_rate
Example:
hostname(config)# threat-detection rate dos-drop rate-interval 600 average-rate 60
burst-rate 100
For a description of each event type, see
Basic Threat Detection Statistics, page 15-2
.
When you use this command with the
scanning-threat
keyword, it is also used in the scanning threat
detection. If you do not configure basic threat detection, you can still use this command with the
scanning-threat
keyword to configure the rate limits for scanning threat detection.
You can configure up to three different rate intervals for each event type.
Configure Advanced Threat Detection Statistics
You can configure the ASA to collect extensive statistics. By default, statistics for ACLs are enabled. To
enable other statistics, perform the following steps.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...