
2-23
Cisco SCE 8000 CLI Command Reference
Chapter 2 CLI Command Reference
attack-detector default
attack-detector default
Defines default thresholds and attack handling action. If a specific attack detector is defined for a
particular situation (protocol, attack direction, or side), the detector overrides the defaults.
To delete the user-defined defaults, use the no form of this command. The system defaults are used
instead.
attack-detector default protocol protocol attack-direction attack-direction side side [action
action] [open-flows open-flows] [ddos-suspected-flows ddos-suspected-flows]
[suspected-flows-ratio suspected-flows-ratio] [notify-subscriber | dont-notify-subscriber]
[alarm |noalarm]
no attack-detector default protocol protocol attack-direction attack-direction side side [action
action] [open-flows open-flows] [ddos-suspected-flows ddos-suspected-flows]
[suspected-flows- ratio suspected-flows-ratio]
Syntax Description
Command Default The default attack detector uses the following default values:
• Action—report
• Thresholds—varies according to the attack type
• Subscriber notification—disabled
• Sending an SNMP trap—disabled
Command Modes Interface Linecard Configuration
Command History This table includes the following release-specific history entries:
protocol For protocol, choose TCP, UDP, IMCP, or other.
attack-direction For attack-direction, choose attack-source, attack-destination, or both.
side For size, choose subscriber, network, or both.
action For action, choose report or block.
open-flows Threshold for concurrently open flows (new open flows per second).
ddos-suspected-flows Threshold for DDoS-suspected flows (new suspected flows per second).
suspected-flows-ratio Threshold for ratio of suspected flow rate to open flow rate.
notify-subscriber,
dont-notify-subscriber
Enables or disables subscriber notification.
alarm, noalarm Enables or disables sending of SNMP traps.
Release Modification
2.5.7 This command was introduced.
Commenti su questo manuale