12-23
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 12 Identifying and Preventing Distributed Denial-of-Service Attacks
Preventing and Forcing Attack Detection
From the SCE(config if)# prompt, type:
How to Remove All force-filter Settings
From the SCE(config if)# prompt, type:
Command
Purpose
attack-filter force-filter action (block|report)
protocol
(((TCP|UDP) [dest-port (port-number
|not-specific))|ICMP|other) attack-direction
(((single-side-source|single-side-destination|single-side-
both) (ip
ip-address
)|(dual-sided source-ip
source-ip-address
destination-ip
dest-ip-address
)) side
(subscriber|network|both)[notify-subscriber]
Configures a force-filter setting for a
specified situation.
no attack-filter force-filter protocol (((TCP|UDP)
[dest-port (port-number |not-specific))|ICMP|other)
attack-direction
(((single-side-source|single-side-destination|single-side-
both) (ip
ip-address
)|(dual-sided source-ip
source-ip-address
destination-ip
dest-ip-address
)) side
(subscriber|network|both)
Removes a force-filter setting from a
specified situation.
Command
Purpose
no attack-filter force-filter all
Removes all force-filter settings.