Avaya BSGx4e CLI User's Guide Page 46

  • Download
  • Add to my manuals
  • Print
  • Page
    / 184
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 45
Intrusion detection system commands 3 Configuration commands
46 NN47928-107
ids scan
IDS scan protection can be activated for ICMP, UDP, and TCP SYN
messages. A threshold value determines the number of messages sent that
constitute an attack. When IDS detects a scan attack, it bans traffic for that
protocol (ICMP, UDP, or TCP) for the timeout interval. This command
activates a scan time or changes the timeout value.
Syntax config ids scan [updportscan|tcpportscan|pingsweep] timeout
<seconds> active [no|yes]
Parameters attack updportscan|tcpportscan|pingsweep
Specify the attack type to scan.
udpportscan — A port scan is a series of
messages sent by a potential system intruder to
determine which services the system provides.
The services are each associated with a well-
known port number. Port scanning suggests
where the intruder can probe for weaknesses.
tcpsynscan A TCP SYN scan is a series of
messages sent with the TCP Syn flag set.
pingsweep
— ICMP requests are sent to
multiple hosts. A ping sweep is a means to
locate network devices that are active and
responding, and so, can be targets for an
attack.
timeout seconds Enter the timeout after an attack is detected.
The default is 50 seconds for udpportscan and
tcpsynscan, and 60 seconds for pingsweep.
active no|yes Enable/disable attack protection.
Example > config ids scan udpportscan timeout 30 active yes
Related
commands
display ids scan
show ids scan
clear ids attacks
show ids attacks
display ids flood settings
show ids flood settings
clear ids attacks
show ids attacks
Page view 45
1 2 ... 41 42 43 44 45 46 47 48 49 50 51 ... 183 184

Comments to this Manuals

No comments