12-11
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 12 Identifying and Preventing Distributed Denial-of-Service Attacks
Configuring Attack Detectors
How to Enable Specific-IP Detection for the TCP Protocol Only for all Attack Directions
From the SCE(config if)# prompt, enter:
How to Enable Specific-IP Detection for the TCP Protocol for Port-Based Detections Only for
Dual-Sided Attacks
From the SCE(config if)# prompt, enter:
How to Disable Specific-IP Detection for Protocols Other than TCP, UDP, and ICMP for all Attack
Directions
From the SCE(config if)# prompt, enter:
How to Disable Specific-IP Detection for ICMP for Single-Sided Attacks Defined by the Source IP
From the SCE(config if)# prompt, enter:
Configuring the Default Attack Detector
•
•
How to Define the Default Action and Optionally, the Default Thresholds, page 12-13
•
How to Reinstate the System Defaults for a Selected Set of Attack Types, page 12-13
•
How to Reinstate the System Defaults for All Attack Types, page 12-14
Command
Purpose
attack-filter protocol TCP
Enables specific-IP detection for the TCP
protocol only for all attack directions.
Command
Purpose
attack-filter protocol TCP dest-port specific
attack-direction dual-sided
Enables specific-IP detection for the TCP
protocol for port-based detections only for
dual-sided attacks.
Command
Purpose
no attack-filter protocol other
Disables specific-IP detection for protocols other
than TCP, UDP, and ICMP for all attack directions.
Command
Purpose
no attack-filter protocol ICMP
attack-direction single-side-source
Disable specific-IP detection for ICMP for
single-sided attacks defined by the source IP.