12-26
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 12 Identifying and Preventing Distributed Denial-of-Service Attacks
Monitoring Attack Filtering
Monitoring Attack Filtering Using CLI Commands
•
How to Display a Specified Attack Detector Configuration, page 12-26
•
How to Display the Default Attack Detector Configuration, page 12-28
•
How to Display All Attack Detector Configurations, page 12-28
•
How to Display Filter State (Enabled or Disabled), page 12-29
•
How to Display Configured Threshold Values and Actions, page 12-29
•
How to Display the Current Counters, page 12-30
•
How to Display all Currently Handled Attacks, page 12-31
•
How to Display all Existing Force-Filter Settings, page 12-31
•
How to Display all Existing Don't-Filter Settings, page 12-31
•
How to Display the List of Ports Selected for Subscriber Notification, page 12-31
•
How to Find out Whether Hardware Attack Filtering has been Activated, page 12-32
Use these commands to monitor attack detection and filtering:
•
show interface linecard 0 attack-detector
•
show interface linecard 0 attack-filter
•
show interface linecard 0 attack-filter query
•
show interface linecard 0 attack-filter current-attacks
•
show interface linecard 0 attack-filter don't-filter
•
show interface linecard 0 attack-filter force-filter
•
show interface linecard 0 attack-filter subscriber-notification ports
How to Display a Specified Attack Detector Configuration
•
•
The following information is displayed:
•
Protocol Side—Whether the attack detector applies to attacks originating at the subscriber or
network side.
•
Direction—Whether the attack detector applies to single sided or dual sided attacks. Action to take
if an attack is detected.
•
Thresholds:
–
open-flows-rate—Default threshold for rate of open flows (new open flows per second).
–
suspected-flows-rate—Default threshold for rate of suspected DDoS flows (new suspected
flows per second).
–
suspected-flows-ratio—Default threshold for ratio of suspected flow rate to open flow rate.
•
Subscriber notification—Enabled or disabled.
•
Alarm: sending an SNMP trap enabled or disabled.