12-16
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 12 Identifying and Preventing Distributed Denial-of-Service Attacks
Configuring Attack Detectors
How to Define the Action and Optionally the Thresholds for a Specific Attack Detector
From the SCE(config if)# prompt, type:
How to Define the Subscriber Notification Setting for a Specific Attack Detector
Use the following command to set the subscriber notification setting for a given attack detector and
selected set of attack types.
From the SCE(config if)# prompt, type:
How to Define the SNMP Trap Setting for a Specific Attack Detector
Use the following command to enable or disable sending an SNMP trap for a given attack detector and
selected set of attack types.
From the SCE(config if)# prompt, type:
Command
Purpose
attack-detector
number
protocol (((TCP|UDP)
[dest-port (specific|not-
specific|both)])|ICMP|other|all)
attack-direction
(single-side-source|single-side-destination|sing
le-side-both|dual-sided|all) side
(subscriber|network|both) [action
(report|block)] [open-flows-rate
number
suspected-flows-rate
rate
suspected-flows-ratio
ratio
]
Defines the action of the specified attack detector.
Command
Purpose
attack-detector
number
protocol (((TCP|UDP)
[dest-port (specific|not-
specific|both)])|ICMP|other|all)
attack-direction
(single-side-source|single-side-destination|sing
le-side-both|dual-sided|all) side
(subscriber|network|both)
(notify-subscriber|don't-notify-subscriber)
Defines the subscriber notification setting for the
specified attack detector.
Command
Purpose
attack-detector
number
protocol (((TCP|UDP)
[dest-port (specific|not-
specific|both)])|ICMP|other|all)
attack-direction
(single-side-source|single-side-destination|sing
le-side-both|dual-sided|all) side
(subscriber|network|both) (alarm|no-alarm)
Defines the SNMP trap setting for the specified
attack detector.