12-17
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 12 Identifying and Preventing Distributed Denial-of-Service Attacks
Configuring Attack Detectors
How to Define the List of Destination Ports for TCP or UDP Protocols for a Specific Attack Detector
Use the following command to define the list of destination ports for specific port detections for TCP or
UDP protocols.
From the SCE(config if)# prompt, type:
How to Delete User-Defined Values
Use the following command to remove settings of action, thresholds, subscriber notification, and
sending an SNMP trap for a specific attack detector and selected set of attack types.
Removing these settings for a given attack type restores them to the default 'not configured' state, which
means that the attack detector does not take part in determining the response for attacks of this attack
type.
From the SCE(config if)# prompt, type:
How to Disable a Specific Attack Detector
Use the following command to disable a specific attack detector, configuring it to use the default action,
threshold values and subscriber notification for all protocols, attack directions and sides.
From the SCE(config if)# prompt, type:
Command
Purpose
attack-detector
number
TCP-port-list|UDP-port-list (all|(
port1
[,
port2,
port3…
])
Defines the port list for the specified protocol and
attack detector.
Command
Purpose
default attack-detector
number
protocol
(((TCP|UDP) [dest-port (specific|not-
specific|both)])|ICMP|other|all)
attack-direction
(single-side-source|single-side-destination|sing
le-side-both|dual-sided|all) side
(subscriber|network|both)
Deletes the configured attack detector settings for
the specified attack type.
Command
Purpose
default attack-detector
number
Disables the specified attack detector.