dosDefenseThreshold
The threshold, in packets per second, at which an attack is deemed to be in progress. If dosDefenseAttackType is SYNFlood(1), a value of 0 means no threshold has been set and the default thresholds apply. An attack is suspected when the SYN:ACK ratio exceeds 2:1 above 20 packets per second, in any one-second interval. An attack is in progress when the SYN:ACK ratio exceeds 3:1 above 20 packets per second, in any one-second interval, or an attack is suspected more than once within a dosDefenseBlockTime interval. If dosDefenseAttackType is Smurf(3), a value of 0 means the filter will block all broadcast ICMP requests. A threshold greater than 0 will block after that number of ICMP requests are received in a 1 second interval.
Table columns
12 objects| Oid | Name | Access | Type |
|---|---|---|---|
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.1 | dosDefensePort | readonly | Unknown |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.2 | dosDefenseAttackType | readonly | synFlood(1), pingOfDeath(2), smurf(3), ipOptions(4), land(5), teardrop(6), none(7) |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.3 | dosDefenseDefenseStatus | readonly | enabled(1), disabled(2), set(3) |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.4 | dosDefenseThreshold | readonly | Unknown |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.5 | dosDefenseBlockTime | readonly | Unknown |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.6 | dosDefenseMirroring | readonly | TruthValue |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.7 | dosDefensePortType | readonly | notApplicable(0), client(1), gateway(2) |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.8 | dosDefenseSubnetAddress | readonly | IpAddress |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.9 | dosDefenseSubnetMask | readonly | IpAddress |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.10 | dosDefenseAttackState | readonly | none(0), suspected(1), inProgress(2) |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.11 | dosDefenseAttackCount | readonly | Counter32 |
| 1.3.6.1.4.1.207.8.4.4.4.143.4.1.12 | dosDefenseRemainingBlockTime | readonly | Unknown |