EasyManuals Logo

Alcatel-Lucent OmniSwitch 6860 Series User Manual

Alcatel-Lucent OmniSwitch 6860 Series
1078 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #338 background imageLoading...
Page #338 background image
Configuring IP IP Configuration
OmniSwitch AOS Release 8 Network Configuration Guide December 2017 page 15-30
Setting the Port Scan Penalty Value Threshold
The port scan penalty value threshold is the highest point the total penalty value for the switch can reach
before a trap is generated informing the administrator that a port scan is in progress.
To set the port scan penalty value threshold, enter the threshold value with the ip dos scan threshold
command. For example, to set the port scan penalty value threshold to 2000, enter the following:
-> ip dos scan threshold 2000
Setting the Decay Value
The decay value is the amount the total penalty value is divided by every minute. As the switch records
incoming UDP and TCP packets, it adds their assigned penalty values together to create the total penalty
value for the switch. To prevent the switch from registering a port scan from normal traffic, the decay
value is set to lower the total penalty value every minute to compensate from normal traffic flow.
To set the decay value, enter the decay value with the ip dos scan decay command. For example, to set
the decay value to 2, enter the following:
-> ip dos scan decay 2
Enabling DoS Traps
Enable the DoS traps for the switch to warn the administrator that a port scan can be in progress when the
total penalty value of the switch crosses the port scan penalty value threshold.
To enable SNMP trap generation, enter the ip dos trap command, as shown:
-> ip dos trap enable
To disable DoS traps, enter the same ip dos trap command, as shown:
-> ip dos trap disable
ARP Poisoning
ARP Poisoning allows an attacker to sniff and tamper the data frames on a network. It also modifies or
halts the traffic. The principle of ARP Poisoning is to send false or spoofed ARP messages to an Ethernet
LAN.
The OmniSwitch introduces the functionality that detects the presence of an ARP poisoning host on a
network. This functionality uses a configured restricted IP addresses, so that the switch does not get ARP
response on sending an ARP request. If an ARP response is received, then an event is logged and the user
is alerted using an SNMP trap.
Use the ip dos arp-poison restricted-address command to add an ARP Poison restricted address. Enter
the command, followed by the IP address. For example, to add an ARP Poison restricted address as
192.168.1.1, you would enter:
-> ip dos arp-poison restricted-address 192.168.1.1
To delete an ARP Poison restricted address, enter no ip dos arp-poison restricted-address followed by
the IP address. For example:
-> no ip dos arp-poison restricted-address 192.168.1.1

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Alcatel-Lucent OmniSwitch 6860 Series and is the answer not in the manual?

Alcatel-Lucent OmniSwitch 6860 Series Specifications

General IconGeneral
BrandAlcatel-Lucent
ModelOmniSwitch 6860 Series
CategorySwitch
LanguageEnglish

Related product manuals