12-13
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 12 Identifying and Preventing Distributed Denial-of-Service Attacks
Configuring Attack Detectors
How to Define the Default Action and Optionally, the Default Thresholds
Defaults
The default values for the default attack detector are:
•
Action—Report
•
Thresholds—Varies according to the attack type
•
Subscriber notification—Disabled
•
Sending an SNMP trap—Disabled
Step 1
From the SCE(config if)# prompt, type
a
ttack-detector default protocol (((TCP|UDP) [dest-port
(specific|not- specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all) side
(subscriber|network|both) [action (report|block)] [open-flows-rate
number
suspected-flows-rate
rate
suspected-flows-ratio
ratio
]
and press
Enter
.
Configures the default attack detector for the defined attack type.
Step 2
From the SCE(config if)# prompt, type
attack-detector default protocol (((TCP|UDP) [dest-port
(specific|not- specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all) side
(subscriber|network|both) (notify-subscriber|don't-notify-subscriber)
and press
Enter
.
Enables or disables subscriber notification by default for the defined attack type.
The attack type must be defined the same as in Step 1.
Step 3
From the SCE(config if)# prompt, type
attack-detector default protocol (((TCP|UDP) [dest-port
(specific|not- specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-side-both|dual-sided|all) side
(subscriber|network|both) (alarm|no-alarm)
and press Enter.
Enables or disables sending an SNMP trap by default for the defined attack type.
The attack type must be defined the same as in Step 1.
How to Reinstate the System Defaults for a Selected Set of Attack Types
Use the following command to delete user-defined default values for action, thresholds, subscriber
notification, and sending an SNMP trap for a selected set of attack types, and reinstate the system
defaults.
From the SCE(config if)# prompt, type:
Command
Purpose
default attack-detector default protocol
(((TCP|UDP) [dest-port (specific|not-
specific|both)])|ICMP|other|all) attack-direction
(single-side-source|single-side-destination|single-si
de-both|dual-sided|all) side
(subscriber|network|both)
Reinstates the system defaults for the defined
attack types.