This command displays the specified denial of service profile information for the Sensor, defined in two arguments — a DoS measure name, and a traffic direction. It also displays the DOS prevention profile information for different measures.
Syntax:
show dospreventionprofile <dos-measure-name> <inbound | outbound>
show dospreventionprofile intfport (g0/1 | g0/2 | g1/1 | g1/2 | g1/3 | g1/4 | g1/5 | g1/6 | g1/7 | g1/8 | g1/9 | g1/10 | g1/11 | g1/12 | g2/1 | g2/2 | g2/3 | g2/4 | g2/5 | g2/6 | g2/7 | g2/8 | g2/9 | g2/10 | g2/11 | g2/12 | g3/1 | g3/2 | g3/3 | g3/4 | g3/5 | g3/6 | g3/7 | g3/8 | g4/1 | g4/2 | g5/1 | g5/2 | g5/3 | g5/4 | g5/5 | g5/6 | g5/7 | g5/8 | g5/9 | g5/10 | g5/11 | g5/12 | g6/1 | g6/2 | g6/3 | g6/4 | g6/5 | g6/6 | g6/7 | g6/8 | g6/9 | g6/10 | g6/11 | g6/12 | g7/1 | g7/2 | g7/3 | g7/4 | g7/5 | g7/6 | g7/7 | g7/8) (tcp-syn|tcp-syn-ack|tcp-fin|tcp-rst|udp|icmp-echo|icmp-echo-reply|icmp-non-echo-echoreply|ip-fragment|non-tcp-udp-icmp) (inbound | outbound)
Parameter | Description |
|---|---|
<intfport> | Indicates the interface port |
<dos-measure-name> | Indicates the DoS measure name: one of 'tcp-syn', 'tcp-syn-ack', 'tcp-fin', 'tcp-rst', 'udp', 'icmp-echo', 'icmp-echo-reply', 'icmp-non-echo-reply', 'ip-fragment', 'non-tcp-udp-icmp' |
<direction> | Indicates the direction. It can be 'inbound' or 'outbound'. |
Example:
show dospreventionprofile tcp-syn inbound
Information displayed by the show dospreventionprofile command includes the following:
The Sensor's DoS profile
The traffic direction protected by the profile
Example 1:
intruShell@Sensor-9500> show dosPreventionProfile tcp-syn inbound
where:
packet type: TCP-SYN IN (0), profile stage: still learning (0)
long-term average rate=0.000(pkts/s), last_rate=0.000(pkts/s) no attack in progress
each line: bin_index, IP_prefix/prefix_len, AS, LT, ST, ltR(ate), stR(ate)
AS(%) -- percentage of the IP address space this bin occupies
LT(%) -- percentage of long-term traffic that falls into this bin
ST(%) -- percentage of short-term traffic that falls into this bin
ltRate -- long-term average traffic rate (in pkts/s) for this bin
stRate -- short-term traffic rate (in pkts/s) for this bin
0: 0.0.0.0/2 AS=25.000% LT=25.000% ST=25.00% ltR=0.000 stR=0.000
1: 128.0.0.0/2 AS=25.000% LT=25.000% ST=25.00% ltR=0.000 stR=0.000
2: 64.0.0.0/2 AS=25.000% LT=25.000% ST=25.00% ltR=0.000 stR=0.000
Example 2:
show dospreventionprofile intfport g2/3 tcp-syn inbound
Applicable to:
NS-series Sensors
Note
show dospreventionprofile intfportcommand is applicable only for NS9300 Sensors.