RedMax EXtreme EX-LRT Guía para resolver problemas Pagina 72

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 142
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 71
Oracle SBC Security Guide
SNMP Traps
Enabling the trap-on-demote-to-deny parameter located in the media-manager-config configuration
element enables SNMP traps to be sent for demotions to the denied queue.
When the IDS license is installed, the apSysMgmtInetAddrWithReasonDOSTrap trap is sent. Otherwise,
only the apSysMgmtInetAddrDOSTrap trap is sent.
The IDS Reporting Feature Group in release S-CX6.4 added the capability for the SBC to send a trap
when the SBC demotes an endpoint to the untrusted queue. Enabling the trap-on-demote-to-untrusted
parameter located in the media-manager-config configuration element enables these. The same
apSysMgmtI-netAddrWithReasonDOSTrap is sent.
When the IDS license is installed and the trap-on-demote-to-deny or trap-on-demote-to-untrusted (S-
CX6.4) parameters are disabled, the apSysMgmtI-netAddrWithReasonDOSTrap trap is not sent from the
SBC, even when an endpoint is demoted.
When sent, the apSysMgmtInetAddrWithReasonDOSTrap contains the following data:
apSysMgmtDOSInetAddressTypeBlocked IP address family (IPv4 or IPv6)
apSysMgmtDOSInetAddressBlocked IP address
apSysMgmtDOSRealmIDBlocked Realm ID
apSysMgmtDOSFromURIThe FROM header of the message that caused the block (If
available)
apSysMgmtDOSReasonThe reason for demoting the endpoint to the denied queue: This field
can report the following three values:
o Too many errors
o Too many messages
o Too many admission control failures
HDR
The SIP (sip-ACL-oper) and MGCP (mgcp-oper) HDR ACL status collection groups include the
following two metrics:
Demote Trust-Untrust - Global counter of endpoint demotion from trusted to untrusted queue
Demote Untrust-Deny - Global counter of endpoint demotion from untrusted to denied queue
TimeStamp ACL Requests Bad Msgs Promo Demo Demote Trust-Untrust Demote Untrust-Deny
1369338880 0 0 0 0 0 0
1369338940 0 0 0 0 0 0
1369339000 0 0 0 0 0 0
1369339060 0 0 0 0 0 0
Syslog
A syslog message can also be generated when an endpoint is demoted. Setting the media-manager config
-> syslog-on-demote-to-deny parameter to enabled writes an endpoint demotion warning to the syslog
every time an endpoint is demoted to the denied queue. In EC[xz]6.4.0 demotions from trusted to
untrusted can also be reported by setting the media-manager -> syslog-on-demote-to-untrusted parameter
to enabled. By default, these configuration options are set to disabled.
Without the IDS Reporting Feature Group license applied, the syslog messages have a WARNING level
and look like this:
Vista de pagina 71
1 2 ... 67 68 69 70 71 72 73 74 75 76 77 ... 141 142

Comentarios a estos manuales

Sin comentarios