ProCurve 6200yl User's Guide Page 424

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 423
11-24
Configuring Advanced Threat Protection
Using the Instrumentation Monitor
Alerts are automatically rate limited to prevent filling the log file with
redundant information. The following is an example of alerts that
occur when the device is continually subject to the same attack (too
many MAC addresses in this instance):
Figure 2. Example of rate limiting when multiple messages are generated
In the preceding example, if a condition is reported 4 times (persists for
more than 15 minutes) then alerts cease for 15 minutes. If after 15 minutes
the condition still exists, the alerts cease for 30 minutes, then for 1 hour,
2 hours, 4 hours, 8 hours, and after that the persisting condition is reported
once a day. As with other event log entries, these alerts can be sent to a
syslog server.
Known Limitations: The instrumentation monitor runs once every
five minutes. The current implementation does not track information
such as the port, MAC, and IP address from which an attack is
received.
Configuring Instrumentation Monitor
The following commands and parameters are used to configure the opera-
tional thresholds that are monitored on the switch. By default, the instrumen-
tation monitor is disabled.
W 01/01/90 00:05:00 inst-mon: Limit for MAC addr count (300) is exceeded (321)
W 01/01/90 00:10:00 inst-mon: Limit for MAC addr count (300) is exceeded (323)
W 01/01/90 00:15:00 inst-mon: Limit for MAC addr count (300) is exceeded (322)
W 01/01/90 00:20:00 inst-mon: Limit for MAC addr count (300) is exceeded (324)
W 01/01/90 00:20:00 inst-mon: Ceasing logs for MAC addr count for 15 minutes
Syntax: [no] instrumentation monitor [parameterName|all] [<low|med|high|limitValue>]
[log] : Enables/disables instrumentation monitoring log so that event log messages
are generated every time there is an event which exceeds a configured threshold.
(Default threshold setting when instrumentation monitoring is enabled: enabled)
[all] : Enables/disables all counter types on the switch but does not enable/disable
instrumentation monitor logging.
(Default threshold setting when enabled: see parameter listings below)
[arp-requests] : The number of arp requests that are processed each minute.
(Default threshold setting when enabled: 1000 (med))
[ip-address-count]: The number of destination IP addresses learned in the IP
forwarding table.
(Default threshold setting when enabled: 1000 (med))
Page view 423
1 2 ... 419 420 421 422 423 424 425 426 427 428 429 ... 595 596

Comments to this Manuals

No comments