dosDefenseAttackState

  • 1.3.6.1.4.1.207.8.4.4.4.143.4.1.10
  • Access readonly
  • Type none(0), suspected(1), inProgress(2)

Whether or not an attack is currently in progress on the port. None(0) means no attack is in progress. If dosDefenseAttackType is SYNFlood(1), Suspected(1) means a SYN Flood attack is suspected. A threshold has not been set, and the default threshold of a SYN:ACK ratio of 2:1 above 20 packets per second has been reached. If dosDefenseAttackType is PingOfDeath(2), Teardrop(5) or Land(6), Suspected means that some suspect packets have been received but have not yet been analysed to determine if an attack exists. InProgress(2) means an attack is in progress.

Details

Possible values
0 none
1 suspected
2 inProgress

Table columns

12 objects
Oid Name Access Type
1.3.6.1.4.1.207.8.4.4.4.143.4.1.1 dosDefensePort readonly Unknown
1.3.6.1.4.1.207.8.4.4.4.143.4.1.2 dosDefenseAttackType readonly synFlood(1), pingOfDeath(2), smurf(3), ipOptions(4), land(5), teardrop(6), none(7)
1.3.6.1.4.1.207.8.4.4.4.143.4.1.3 dosDefenseDefenseStatus readonly enabled(1), disabled(2), set(3)
1.3.6.1.4.1.207.8.4.4.4.143.4.1.4 dosDefenseThreshold readonly Unknown
1.3.6.1.4.1.207.8.4.4.4.143.4.1.5 dosDefenseBlockTime readonly Unknown
1.3.6.1.4.1.207.8.4.4.4.143.4.1.6 dosDefenseMirroring readonly TruthValue
1.3.6.1.4.1.207.8.4.4.4.143.4.1.7 dosDefensePortType readonly notApplicable(0), client(1), gateway(2)
1.3.6.1.4.1.207.8.4.4.4.143.4.1.8 dosDefenseSubnetAddress readonly IpAddress
1.3.6.1.4.1.207.8.4.4.4.143.4.1.9 dosDefenseSubnetMask readonly IpAddress
1.3.6.1.4.1.207.8.4.4.4.143.4.1.10 dosDefenseAttackState readonly none(0), suspected(1), inProgress(2)
1.3.6.1.4.1.207.8.4.4.4.143.4.1.11 dosDefenseAttackCount readonly Counter32
1.3.6.1.4.1.207.8.4.4.4.143.4.1.12 dosDefenseRemainingBlockTime readonly Unknown

Comments