Enterasys Networks XSR CLI Router User Manual


 
Security Clear and Show Commands
16-92 Configuring Security
show access-list log-update-threshold
ThiscommanddisplaysACLloginformation.Itisprocessedasfollows:
•ApacketwithafreshsourceIPaddressontheACLgroupisreportedimmediately.Datais
cachedtokeeptrackoftheoccurrencehappeningagaininthenearfuture.
•AllotherarrivalsofthepacketwithexistingsourceIPaddress
dataonthatACLgroupwill
incrementthenumberofpacketsand,afterfiveminutes,loganalarmwiththesumofpackets
gatheredinthelastfiveminutes.Thecountwillresetafterthealarmislogged.
•Forenabledthresholddata,ifthecountmatchesthethresholdthenthealarm
isloggedand
thecountreset.Otherpacketsreceivedafterthethresholdismetwillincrementthecount
untilthenextthresholdismetorfiveminuteshaveelapsed.
Syntax
show access-list log-update-threshold
Mode
PrivilegedEXECorGlobalconfiguration:XSR# or XSR(config)#
Sample Output
ThefollowingexampledisplaysasampleACLlog:
XSR#show access-list log-update-threshold
access-list log-update-threshold 10000
show hostdos
Thiscommanddisplaysenabledhostsecurityfeaturesandtheirstatistics.
Syntax
show hostdos
Mode
PrivilegedEXECorGlobalconfiguration:XSR# or XSR(config)#
Sample Output
Thefollowingexampledisplaysasamplehostsecurityconfigurationwithstatistics:
XSR#show hostdos
LANd Attack (Destination IP = Source IP}
Enabled
10 attacks
Spoofed Address Check
Enabled
0 attacks