This command displays the specified denial of service profile information for the Sensor, defined in two arguments — a DoS measure name, and a traffic direction. It also displays the DOS prevention profile information for different measures.
Syntax:
show dospreventionprofile <dos-measure-name> <inbound | outbound>
show dospreventionprofile intfport (1A|1B|2A|2B|3A|3B|4A|4B|5A|5B|6A|6B|7A|7B|8A|8B|9A|9B|10A|10B|11A|11B|12A|12B|13A|13B|14A|14B) (tcp-syn|tcp-syn-ack|tcp-fin|tcp-rst|udp|icmp-echo|icmp-echo-reply|icmp-non-echo-echoreply|ip-fragment|non-tcp-udp-icmp) (inbound|outbound)
| Parameter | Description |
|---|---|
| <intfport> | Indicates the interface port |
| <dos-measure-name> | Indicates the DoS measure name: one of 'tcp-syn', 'tcp-syn-ack', 'tcp-fin', 'tcp-rst', 'udp', 'icmp-echo', 'icmp-echo-reply', 'icmp-non-echo-reply', 'ip-fragment', 'non-tcp-udp-icmp' |
| <direction> | Indicates the direction. It can be 'inbound' or 'outbound'. |
Example:
show dospreventionprofile tcp-syn inbound
Information displayed by the show dospreventionprofile command includes the following:
- The Sensor's DoS profile
- The traffic direction protected by the profile
Example:
intruShell> show dosPreventionProfile tcp-syn inbound
where:
- packet type: TCP-SYN IN (0), profile stage: still learning (0)
- long-term average rate=0.000(pkts/s), last_rate=0.000(pkts/s) no attack in progress
- each line: bin_index, IP_prefix/prefix_len, AS, LT, ST, ltR(ate), stR(ate)
- AS(%) -- percentage of the IP address space this bin occupies
- LT(%) -- percentage of long-term traffic that falls into this bin
- ST(%) -- percentage of short-term traffic that falls into this bin
- ltRate -- long-term average traffic rate (in pkts/s) for this bin
- stRate -- short-term traffic rate (in pkts/s) for this bin
- 0: 0.0.0.0/2 AS=25.000% LT=25.000% ST=25.00% ltR=0.000 stR=0.000
- 1: 128.0.0.0/2 AS=25.000% LT=25.000% ST=25.00% ltR=0.000 stR=0.000
- 2: 64.0.0.0/2 AS=25.000% LT=25.000% ST=25.00% ltR=0.000 stR=0.000
Example:
show dospreventionprofile intfport 1A tcp-syn inbound
Applicable to:
NS-series Sensors