12-10
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 12 Identifying and Preventing Distributed Denial-of-Service Attacks
Configuring Attack Detectors
Enabling Specific-IP Detection
•
•
How to Enable Specific-IP Detection, page 12-10
•
How to Enable Specific-IP Detection for the TCP Protocol Only for all Attack Directions,
page 12-11
•
•
•
By default, specific-IP detection is enabled for all attack types. You can configure specific IP detection
to be enabled or disabled for a specific, defined situation only, depending on the following options:
•
For a selected protocol only.
•
For TCP and UDP protocols, for only port-based or only port-less detections.
•
For a selected attack direction, either for all protocols or for a selected protocol.
Options
The following options are available:
•
protocol—
The specific protocol for which specific IP detection is to be enabled or disabled.
–
Default—All protocols (no protocol specified)
•
attack direction—
Defines whether specific IP detection is enabled or disabled for single sided or
dual sided attacks.
–
Default—All directions
•
destination port (
TCP and UDP protocols only)—Defines whether specific IP detection is enabled
or disabled for port-based or port-less detections.
–
Default—Both port-based or port-less
•
Use the
no
form of the command to disable the configured specific-IP detection.
How to Enable Specific-IP Detection
From the SCE(config if)# prompt, enter:
Command
Purposes
attack-filter [protocol (((TCP|UDP) [dest-port
(specific|not-specific|both)])|ICMP|other)]
[attack-direction
(single-side-source|single-side-destination|sing
le-side-both|dual-sided|all)]
Enables specific-IP detection.