dosDefenseThreshold

  • 1.3.6.1.4.1.207.8.4.4.4.143.4.1.4
  • Access readonly
  • Type Unknown

The threshold, in packets per second, at which an attack is deemed to be in progress. If dosDefenseAttackType is SYNFlood(1), a value of 0 means no threshold has been set and the default thresholds apply. An attack is suspected when the SYN:ACK ratio exceeds 2:1 above 20 packets per second, in any one-second interval. An attack is in progress when the SYN:ACK ratio exceeds 3:1 above 20 packets per second, in any one-second interval, or an attack is suspected more than once within a dosDefenseBlockTime interval. If dosDefenseAttackType is Smurf(3), a value of 0 means the filter will block all broadcast ICMP requests. A threshold greater than 0 will block after that number of ICMP requests are received in a 1 second interval.

Table columns

12 objects
Oid Name Access Type
1.3.6.1.4.1.207.8.4.4.4.143.4.1.1 dosDefensePort readonly Unknown
1.3.6.1.4.1.207.8.4.4.4.143.4.1.2 dosDefenseAttackType readonly synFlood(1), pingOfDeath(2), smurf(3), ipOptions(4), land(5), teardrop(6), none(7)
1.3.6.1.4.1.207.8.4.4.4.143.4.1.3 dosDefenseDefenseStatus readonly enabled(1), disabled(2), set(3)
1.3.6.1.4.1.207.8.4.4.4.143.4.1.4 dosDefenseThreshold readonly Unknown
1.3.6.1.4.1.207.8.4.4.4.143.4.1.5 dosDefenseBlockTime readonly Unknown
1.3.6.1.4.1.207.8.4.4.4.143.4.1.6 dosDefenseMirroring readonly TruthValue
1.3.6.1.4.1.207.8.4.4.4.143.4.1.7 dosDefensePortType readonly notApplicable(0), client(1), gateway(2)
1.3.6.1.4.1.207.8.4.4.4.143.4.1.8 dosDefenseSubnetAddress readonly IpAddress
1.3.6.1.4.1.207.8.4.4.4.143.4.1.9 dosDefenseSubnetMask readonly IpAddress
1.3.6.1.4.1.207.8.4.4.4.143.4.1.10 dosDefenseAttackState readonly none(0), suspected(1), inProgress(2)
1.3.6.1.4.1.207.8.4.4.4.143.4.1.11 dosDefenseAttackCount readonly Counter32
1.3.6.1.4.1.207.8.4.4.4.143.4.1.12 dosDefenseRemainingBlockTime readonly Unknown

Comments