15-7
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 15 Threat Detection
Configure Threat Detection
The
rate-interval
keyword sets the size of the history monitoring window, between 1 and 1440 minutes.
The default is 30 minutes. During this interval, the ASA samples the number of attacks 30 times.
The
burst-rate
keyword sets the threshold for syslog message generation, between 25 and 2147483647.
The default is 400 per second. When the burst rate is exceeded, syslog message 733104 is generated.
The
average-rate
keyword sets the average rate threshold for syslog message generation, between 25
and 2147483647. The default is 200 per second. When the average rate is exceeded, syslog message
733105 is generated.
Note
This command is available in multiple context mode, unlike the other threat-detection
commands.
Configure Scanning Threat Detection
You can configure scanning threat detection to identify attackers and optionally shun them.
Procedure
Step 1
Enable scanning threat detection.
threat-detection scanning-threat
[
shun
[
except
{
ip-address
ip_address mask
|
object-group
network_object_group_id
}]]
Example:
hostname(config)# threat-detection scanning-threat shun except ip-address 10.1.1.0
255.255.255.0
By default, the system log message 733101 is generated when a host is identified as an attacker. Enter
this command multiple times to identify multiple IP addresses or network object groups to exempt from
shunning.
Step 2
(Optional) Set the duration of the shun for attacking hosts.
threat-detection scanning-threat shun duration
seconds
Example:
hostname(config)# threat-detection scanning-threat shun duration 2000
Step 3
(Optional) Change the default event limit for when the ASA identifies a host as an attacker or as a target.
threat-detection rate scanning-threat rate-interval
rate_interval
average-rate
av_rate
burst-rate
burst_rate
Example:
hostname(config)# threat-detection rate scanning-threat rate-interval 1200 average-rate 10
burst-rate 20
hostname(config)# threat-detection rate scanning-threat rate-interval 2400 average-rate 10
burst-rate 20
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...