Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Define Attack Audit Actions

Sep 15,2009 by alperen

image

Use the global configuration mode command ip audit attack to specify the default action(s) for attack-type signatures. Use the no form of this command to set the default action for info signatures. The syntax is

Rtr1(config)#ip audit attack {action [alarm] [drop] [reset]}
Rtr1(config)#no ip audit info

action

Sets an action for the info signature to take when a match occurs

alarm

Sends an alarm to the console, IDS Director, or to a Syslog server

drop

Drops the packet

reset

Resets the TCP session

This command was introduced in IOS 12.0(5)T. The default action is alarm.

In this example, the default action for attack signatures is set to all three actions:

Rtr1(config)#ip audit attack action alarm drop reset


247 times read

Related news

» Create Named Audit Rules
by alperen posted on Sep 15,2009
» Define Info Audit Actions
by alperen posted on Sep 15,2009
» The show ip audit all Command
by alperen posted on Sep 16,2009
» The show ip audit configuration Command
by alperen posted on Sep 16,2009
» Creating an Audit Rule
by alperen posted on Sep 15,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author