12-24
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 12 Identifying and Preventing Distributed Denial-of-Service Attacks
Monitoring Attack Filtering
Monitoring Attack Filtering
•
Monitoring Attack Filtering Using SNMP Traps, page 12-24
•
Monitoring Attack Filtering Using CLI Commands, page 12-26
•
Viewing the Attack Log, page 12-32
There are three options for monitoring attack filtering and detection:
•
CLI show commands
•
SNMP attack detection traps
•
Attack log
Monitoring Attack Filtering Using SNMP Traps
The system sends a trap at the start of a specific attack detection event, and also when a specific detection
event ends, as follows:
•
STARTED_FILTERING trap – String with the attack information
•
STOPPED_FILTERING
–
String with the attack information
–
String with the reason for stopping
The format of the attack-information string sent when an attack begins is:
•
If attack was detected in the traffic:
Attack detected: Attack ‘IP-info’ from ‘side’ side, protocol ‘protocol’. ‘rate1’ open
flows per second detected, ‘rate2’ Ddos-suspected flows per second detected. Action
is: 'action'.
•
If attack was declared as a result of a
force-filter
command:
Attack Filter: Forced ‘forced-action’ ‘IP-info’ from ‘side’ side, protocol ‘protocol’.
Attack forced using a force-filter command.
The format of the attack-information string sent when an attack ends is:
•
If attack was detected in the traffic:
End-of-attack detected: Attack ‘IP-info’ from ‘side’ side , protocol ‘protocol’.
Action is: ‘action’ Duration ‘duration’ seconds, ‘total-flows’ ‘hw-filter’
•
If the end of the attack was declared as a result of a
no force-filter
command or a new
don't-filter
command:
Attack Filter: Forced to end 'action2' 'IP-info' from 'side' side, protocol
'protocol'. Attack end forced using a 'no force-filter' or a 'don't-filter' command.
The format of the reason string sent when an attack begins is:
•
If attack end was detected in the traffic:
Detected attack end
•
If the end of the attack was declared as a result of a
no force-filter
command or a new
don't-filter
command:
Forced attack end