CiscoメーカーOL-6109-01の使用説明書/サービス説明書
ページ先へ移動 of 22
CH A P T E R 4-1 Cisco Traffic Anomaly De tector User Guide OL-6109-01 4 Zone Configuration This chapter d escribes zone conf iguration. It includes the follo wi ng major sections: • Basic Zone Conf.
Chapter 4 Z one Configuration Basic Zone Config uration 4-2 Cisco Traffic Anomaly Detector User Guide OL-6109-01 • Remov ing a Zone IP Addr ess • Remov ing all Zone IP Addresses Defining a New Zone The Detector enables the us er to define a ne w zone based on a v ariety of templates.
4-3 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Basic Zone Configuration Note If no zone template is specif ied, the zone will be def ined using the Detector DEF A UL T zone template. – base-zone-name —(Optional) The name of a desired zon e used as a template for the ne w zone.
Chapter 4 Z one Configuration Basic Zone Config uration 4-4 Cisco Traffic Anomaly Detector User Guide OL-6109-01 2. Choose ENTER . The following prompt appears: admin@DETECTOR–conf-zone-<new-zone-name># T o duplicate a zone from the zon e command group le vel perform the fol lowing: 1.
4-5 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Basic Zone Configuration Removing All Zones The user may remov e all the Detector’ s zones. Caution Remov ing all zones eliminat es their DDoS detection. T o remov e all zones perform the follo wing: 1.
Chapter 4 Z one Configuration Basic Zone Config uration 4-6 Cisco Traffic Anomaly Detector User Guide OL-6109-01 Where: – template-name —A zone template.
4-7 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Basic Zone Configuration Where zone-name specif ies the desired zone name.
Chapter 4 Z one Configuration Basic Zone Config uration 4-8 Cisco Traffic Anomaly Detector User Guide OL-6109-01 – ip-mask —(Optional) The zone IP subnet mask. Note If no mask is specified, the D etector assum es the default su bnet mask 255.255.255.
4-9 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Zone Remote Guard List Note If no mask is specified, the D etector assum es the default su bnet mask 255.255.255.255 . 2. Choose ENTER . Below is an e x ample of the no ip address command implemen tatio n: admin@DETECTOR-conf-zone-scannet# no ip address 192.
Chapter 4 Z one Configuration Zone Remote Gu ard List 4-10 Cisco Traffic Anomaly Detector User Guide OL-6109-01 This section contains the follo w ing procedures: • Adding a Guard to the Zo ne Remote.
4-11 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Zone Remote Guard List Where remote-guard-a ddress specifies the remote Guard IP address.
Chapter 4 Z one Configuration Zone Traffic Learning 4-12 Cisco Traffic Anomaly Detector User Guide OL-6109-01 T o create a ne w zone with interacti ve recommendations mod e perform the follo wing: 1. From the Conf iguration command grou p lev el type the follo wing: admin@DETECTOR-conf# zone < new-zone-name > interactive 2.
4-13 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Zone Traffic Le arning The Detector’ s too ls for constructing detection policies are the Polic y T empl a tes.
Chapter 4 Z one Configuration Zone Traffic Learning 4-14 Cisco Traffic Anomaly Detector User Guide OL-6109-01 Where zone-name specifies a zone name. Note that the Guard enables the use of an asteri sk (*) as a wildcard denoting either of the follo wing option s: – All of the Guard’ s zones.
4-15 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Zone Traffic Le arning Accepting Learning Phase 1 – Policy Construction The user may accept the Detector’ s suggested pol icies. T o accept the results of the initial Po licy Construction phase perform the follo wing: 1.
Chapter 4 Z one Configuration Zone Traffic Learning 4-16 Cisco Traffic Anomaly Detector User Guide OL-6109-01 Note that the Detector enable s the us e of an asterisk (*) as a wildcard denoting either o f the follow ing options: – All of the Detector’ s zones.
4-17 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Zone Traffic Le arning Terminating Learning Phase 2 – Threshold Tuning After a suf ficie nt period of time (see the abo ve note) the user ends the Threshold T uning phase.
Chapter 4 Z one Configuration Zone Traffic Learning 4-18 Cisco Traffic Anomaly Detector User Guide OL-6109-01 Aborting Learning Phas e 2 – Tuning Threshold The user may wish to abort the second phase of learning procedure. In this case the Detector stops the process and erases the data learned on the se cond phase.
4-19 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Zone Detection 2. Choose ENTER . The follo wing (partial sample) scr een appears: admin@DETECTOR-conf-zone-scannet# show policies statistics Key Rate Policy 192.168.
Chapter 4 Z one Configuration Zone Detection 4-20 Cisco Traffic Anomaly Detector User Guide OL-6109-01 Note that the Detector enable s the us e of an asterisk (*) as a wildcard denoting either o f the follow ing options: – All of the Detector’ s zones.
4-21 Cisco Traffic Anomaly De tector User Guide OL-6109-01 Chapter 4 Zone Configuration Zone Detection Where: – all-zone —The Detector activ ates the Guard to assume protection ov er the ov erall z one whenev er a traff ic abnormality is detected (see this section’ s e xplanation for further details).
Chapter 4 Z one Configuration Zone Detection 4-22 Cisco Traffic Anomaly Detector User Guide OL-6109-01 The sample screen indicates that zone tr aff ic is mirrored (or split), the Detector recei ves the zone’ s traf f i c and the traf fi c sho ws normal flow fluctuatio ns.
デバイスCisco OL-6109-01の購入後に(又は購入する前であっても)重要なポイントは、説明書をよく読むことです。その単純な理由はいくつかあります:
Cisco OL-6109-01をまだ購入していないなら、この製品の基本情報を理解する良い機会です。まずは上にある説明書の最初のページをご覧ください。そこにはCisco OL-6109-01の技術情報の概要が記載されているはずです。デバイスがあなたのニーズを満たすかどうかは、ここで確認しましょう。Cisco OL-6109-01の取扱説明書の次のページをよく読むことにより、製品の全機能やその取り扱いに関する情報を知ることができます。Cisco OL-6109-01で得られた情報は、きっとあなたの購入の決断を手助けしてくれることでしょう。
Cisco OL-6109-01を既にお持ちだが、まだ読んでいない場合は、上記の理由によりそれを行うべきです。そうすることにより機能を適切に使用しているか、又はCisco OL-6109-01の不適切な取り扱いによりその寿命を短くする危険を犯していないかどうかを知ることができます。
ですが、ユーザガイドが果たす重要な役割の一つは、Cisco OL-6109-01に関する問題の解決を支援することです。そこにはほとんどの場合、トラブルシューティング、すなわちCisco OL-6109-01デバイスで最もよく起こりうる故障・不良とそれらの対処法についてのアドバイスを見つけることができるはずです。たとえ問題を解決できなかった場合でも、説明書にはカスタマー・サービスセンター又は最寄りのサービスセンターへの問い合わせ先等、次の対処法についての指示があるはずです。