6-32
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 6 Global Configuration
OS Fingerprinting and NAT Detection
Step 4
os
-fingerprinting
Example:
SCE(config if)# os-fingerprinting
Enables OS fingerprinting and loads the
default.fp
signature file.
Step 5
os-fingerprinting sampling window
window
interval
interval
Example:
SCE(config if)# os-fingerprinting sampling window
60
interval
5
(Optional) Configures the following:
•
Length of the OS sampling window, in seconds
(10-300)
•
Interval between sampling windows, in minutes
(10-1440)
Step 6
os-fingerprinting NAT-detection-window
time
Example:
SCE(config if)# os-fingerprinting
NAT-detection-window
600
(Optional) Enables NAT detection and configures the
time period, in seconds, within which detecting
multiple operating systems for one subscriber will
trigger NAT identification. (10-300)
Step 7
os-fingerprinting os-flush-time
time
Example:
SCE(config if)# os-fingerprinting os-flush-time 3
(Optional) Enables flushing the OS fingerprinting
information and configures the time interval, in days,
after which OS fingerprinting information is flushed
from the system. (1-5)
Step 8
os-fingerprinting signature-file
filename
Example:
SCE(config if)# os-fingerprinting signature-file
new-signature-file
(Optional) Specifies the signature file used for OS
fingerprinting.
Step 9
os-fingerprinting scan-port
port#
Example:
SCE(config if)# os-fingerprinting scan-port
50
(Optional) Configures the port used for opening OS
fingerprinting flows. The port numbers can be in the
range of 0 - 65535. However, the following port
numbers are blocked, and cannot be used for OS
fingerprinting:
20, 21, 194, 554, 651, 654, 1720, 1755, 2000, 2948,
2949, 4374, 5060, 5061.
For more information on this command, see the
Cisco SCE 8000 CLI Command Reference,
Release 3.7.x
.
Step 10
os
-fingerprinting gx-report
Example:
SCE(config if)# os-fingerprinting gx-report
(Optional) Enables sending subscriber OS information
in Gx messages.
Command
Purpose