A:ALA-4# show system security access-group
===============================================================================
Access Groups
===============================================================================
group name security security read write notify
model level view view view
-------------------------------------------------------------------------------
snmp-ro snmpv1 none no-security no-security
snmp-ro snmpv2c none no-security no-security
snmp-rw snmpv1 none no-security no-security no-security
snmp-rw snmpv2c none no-security no-security no-security
snmp-rwa snmpv1 none iso iso iso
snmp-rwa snmpv2c none iso iso iso
snmp-trap snmpv1 none iso
snmp-trap snmpv2c none iso
===============================================================================
A:ALA-7#
A:ALA-4# show system security authentication
===============================================================================
Authentication sequence : radius tacplus local
===============================================================================
server address status type timeout(secs) single connection retry count
-------------------------------------------------------------------------------
10.10.10.103 up radius 5 n/a 5
10.10.0.1 up radius 5 n/a 5
10.10.0.2 up radius 5 n/a 5
10.10.0.3 up radius 5 n/a 5
-------------------------------------------------------------------------------
radius admin status : down
tacplus admin status : up
health check : enabled
-------------------------------------------------------------------------------
No. of Servers: 4
===============================================================================
A:ALA-4#
A:ALA-7>show>system>security# authentication statistics
===============================================================================
Authentication sequence : radius tacplus local
===============================================================================
server address status type timeout(secs) single connection retry count
-------------------------------------------------------------------------------
10.10.10.103 up radius 5 n/a 5
10.10.0.1 up radius 5 n/a 5
10.10.0.2 up radius 5 n/a 5
10.10.0.3 up radius 5 n/a 5
-------------------------------------------------------------------------------
radius admin status : down
tacplus admin status : up
health check : enabled
-------------------------------------------------------------------------------
No. of Servers: 4
===============================================================================
Login Statistics
===============================================================================
server address connection errors accepted logins rejected logins
-------------------------------------------------------------------------------
10.10.10.103 0 0 0
10.10.0.1 0 0 0
10.10.0.2 0 0 0
10.10.0.3 0 0 0
local n/a 1 0
===============================================================================
Authorization Statistics (TACACS+)
===============================================================================
server address connection errors sent packets rejected packets
-------------------------------------------------------------------------------
===============================================================================
Accounting Statistics
===============================================================================
server address connection errors sent packets rejected packets
-------------------------------------------------------------------------------
10.10.10.103 0 0 0
10.10.0.1 0 0 0
10.10.0.2 0 0 0
10.10.0.3 0 0 0
===============================================================================
A:ALA-7#
*A:Dut-C# show system security authentication statistics
==============================================================================
Authentication sequence : radius tacplus local
==============================================================================
type status timeout single retry
server address (secs) conn count
------------------------------------------------------------------------------
------------------------------------------------------------------------------
health check : enabled (interval 30)
===============================================================================
Login Statistics
===============================================================================
server address conn accepted rejected
errors logins logins
-------------------------------------------------------------------------------
local n/a 4 0
===============================================================================
Authorization Statistics (TACACS+)
===============================================================================
server address conn sent rejected
errors pkts pkts
-------------------------------------------------------------------------------
===============================================================================
Accounting Statistics
===============================================================================
server address conn sent rejected
errors pkts pkts
-------------------------------------------------------------------------------
==============================================================================
A:ALA-48# show system security communities
=============================================================================
Communities
=============================================================================
community access view version group name
-----------------------------------------------------------------------------
cli-readonly r iso v2c cli-readonly
cli-readwrite rw iso v2c cli-readwrite
public r no-security v1 v2c snmp-ro
-----------------------------------------------------------------------------
No. of Communities: 3
=============================================================================
A:ALA-48#
A:ALA-35# show system security cpm-filter ip-filter
===============================================================================
CPM IP Filters
===============================================================================
Entry-Id Dropped Forwarded Description
-------------------------------------------------------------------------------
101 25880 0 CPM-Filter 10.4.101.2 #101
102 25880 0 CPM-Filter 10.4.102.2 #102
103 25880 0 CPM-Filter 10.4.103.2 #103
104 25882 0 CPM-Filter 10.4.104.2 #104
105 25926 0 CPM-Filter 10.4.105.2 #105
106 25926 0 CPM-Filter 10.4.106.2 #106
107 25944 0 CPM-Filter 10.4.107.2 #107
108 25950 0 CPM-Filter 10.4.108.2 #108
109 25968 0 CPM-Filter 10.4.109.2 #109
110 25984 0 CPM-Filter 10.4.110.2 #110
111 26000 0 CPM-Filter 10.4.111.2 #111
112 26018 0 CPM-Filter 10.4.112.2 #112
113 26034 0 CPM-Filter 10.4.113.2 #113
114 26050 0 CPM-Filter 10.4.114.2 #114
115 26066 0 CPM-Filter 10.4.115.2 #115
116 26084 0 CPM-Filter 10.4.116.2 #116
===============================================================================
A:ALA-35#
A:ALA-35# show system security cpm-filter ip-filter entry 101
===============================================================================
CPM IP Filter Entry
===============================================================================
Entry Id : 101
Description : CPM-Filter 10.4.101.2 #101
-------------------------------------------------------------------------------
Filter Entry Match Criteria :
-------------------------------------------------------------------------------
Log Id : n/a
Src. IP : 10.4.101.2/32 Src. Port : 0
Dest. IP : 10.4.101.1/32 Dest. Port : 0
Protocol : 6 Dscp : ef
ICMP Type : Undefined ICMP Code : Undefined
Fragment : True Option-present : Off
IP-Option : 130/255 Multiple Option : True
TCP-syn : Off TCP-ack : True
Match action : Drop
===============================================================================
A:ALA-35#
A:ALA-35# show system security cpm-filter ipv6-filter
===============================================================================
CPM IPv6 Filters
===============================================================================
Entry-Id Dropped Forwarded Description
-------------------------------------------------------------------------------
101 25880 0 CPM-Filter 11::101:2 #101
102 25880 0 CPM-Filter 11::102:2 #102
103 25880 0 CPM-Filter 11::103:2 #103
104 25880 0 CPM-Filter 11::104:2 #104
105 25880 0 CPM-Filter 11::105:2 #105
106 25880 0 CPM-Filter 11::106:2 #106
107 25880 0 CPM-Filter 11::107:2 #107
108 25880 0 CPM-Filter 11::108:2 #108
109 25880 0 CPM-Filter 11::109:2 #109
===============================================================================
A:ALA-35#
A:ALA-35# show system security cpm-filter ipv6-filter entry 101
===============================================================================
CPM IPv6 Filter Entry
===============================================================================
Entry Id : 1
Description : CPM-Filter 11::101:2 #101
-------------------------------------------------------------------------------
Filter Entry Match Criteria :
-------------------------------------------------------------------------------
Log Id : n/a
Src. IP : 11::101:2 Src. Port : 0
Dest. IP : 11::101:1 Dest. Port : 0
next-header : none Dscp : Undefined
ICMP Type : Undefined ICMP Code : Undefined
TCP-syn : Off TCP-ack : Off
Match action : Drop
Dropped pkts : 25880 Forwarded pkts : 0
===============================================================================
A:ALA-35#
A:ALA-35# show system security cpm-queue 1001
===============================================================================
CPM Queue Entry
===============================================================================
Queue Id : 1001
-------------------------------------------------------------------------------
Queue Parameters :
-------------------------------------------------------------------------------
PIR : 10000000 CIR : 1000000
CBS : 4096 MBS : 8192
===============================================================================
A:ALA-35#
show system security cpu-protection eth-cfm-monitoring
===============================================================================
SAP's where the protection policy Eth-CFM rate limit is exceeded
===============================================================================
SAP-Id Service-Id Plcy
-------------------------------------------------------------------------------
1/1/1 3 100
-------------------------------------------------------------------------------
1 SAP('s) found
===============================================================================
===============================================================================
SDP's where the protection policy Eth-CFM rate limit is exceeded
===============================================================================
SDP-Id Service-Id Plcy
-------------------------------------------------------------------------------
1:3 3 100
-------------------------------------------------------------------------------
1 SDP('s) found
===============================================================================
show system security cpu-protection eth-cfm-monitoring service-id 3 sap-id 1/1/1
===============================================================================
Flows exceeding the Eth-CFM monitoring rate limit
===============================================================================
Service-Id : 3
SAP-Id : 1/1/1
Plcy : 100
-------------------------------------------------------------------------------
Limit MAC-Address Level OpCode
First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
0 8c:8c:8c:8c:8c:8c 1 18
03/21/2009 23:32:29 03/21/2009 23:34:39 4000000019
61234 8d:8d:8d:8d:8d:8d 2 19
03/21/2009 23:32:39 03/21/2009 23:34:59 4000000020
61234 Aggregated 3 20
03/21/2009 23:32:49 03/21/2009 23:35:19 4000000021
61234 8f:8f:8f:8f:8f:8f 4 21
03/21/2009 23:32:59 03/21/2009 23:35:39 4000000022
61234 90:90:90:90:90:90 5 22
03/21/2009 23:33:09 03/21/2009 23:35:59 4000000023
61234 91:91:91:91:91:91 6 23
03/21/2009 23:33:19 03/21/2009 23:36:19 4000000024
61234 92:92:92:92:92:92 7 24
03/21/2009 23:33:29 03/21/2009 23:36:39 4000000025
max Aggregated 0 25
03/21/2009 23:33:39 03/21/2009 23:36:59 4000000026
0 94:94:94:94:94:94 1 26
03/21/2009 23:33:49 03/21/2009 23:37:19 4000000027
-------------------------------------------------------------------------------
9 flows(s) found
===============================================================================
show system security cpu-protection eth-cfm-monitoring service-id 3 sdp-id 1:3
===============================================================================
Flows exceeding the Eth-CFM monitoring rate limit
===============================================================================
Service-Id : 3
SDP-Id : 1:3
Plcy : 100
-------------------------------------------------------------------------------
Limit MAC-Address Level OpCode
First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
0 8c:8c:8c:8c:8c:8c 1 18
03/21/2009 23:32:29 03/21/2009 23:34:39 3000000019
61234 8d:8d:8d:8d:8d:8d 2 19
03/21/2009 23:32:39 03/21/2009 23:34:59 3000000020
61234 Aggregated 3 20
03/21/2009 23:32:49 03/21/2009 23:35:19 3000000021
61234 8f:8f:8f:8f:8f:8f 4 21
03/21/2009 23:32:59 03/21/2009 23:35:39 3000000022
61234 90:90:90:90:90:90 5 22
03/21/2009 23:33:09 03/21/2009 23:35:59 3000000023
61234 91:91:91:91:91:91 6 23
03/21/2009 23:33:19 03/21/2009 23:36:19 3000000024
61234 92:92:92:92:92:92 7 24
03/21/2009 23:33:29 03/21/2009 23:36:39 3000000025
max Aggregated 0 25
03/21/2009 23:33:39 03/21/2009 23:36:59 3000000026
0 94:94:94:94:94:94 1 26
03/21/2009 23:33:49 03/21/2009 23:37:19 3000000027
-------------------------------------------------------------------------------
9 flow(s) found
===============================================================================
show system security cpu-protection excessive-sources service-id 3 sdp-id 1:3
===============================================================================
Sources exceeding the per-source rate limit
===============================================================================
Service-Id : 3
SDP-Id : 1:3
Plcy : 100
Limit : 65534
-------------------------------------------------------------------------------
MAC-Address First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
00:00:00:00:00:01 03/22/2009 00:41:59 03/22/2009 01:53:39 3000000043
00:00:00:00:00:02 03/22/2009 00:43:39 03/22/2009 01:56:59 3000000044
00:00:00:00:00:03 03/22/2009 00:45:19 03/22/2009 02:00:19 3000000045
00:00:00:00:00:04 03/22/2009 00:46:59 03/22/2009 02:03:39 3000000046
00:00:00:00:00:05 03/22/2009 00:48:39 03/22/2009 02:06:59 3000000047
-------------------------------------------------------------------------------
5 source(s) found
===============================================================================
show system security cpu-protection violators sdp
===============================================================================
SDP's where the protection policy overall rate limit is violated
===============================================================================
SDP-Id Service-Id
Plcy Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
1:1 3
100 61234 05/01/2010 01:43:53 06/27/2010 22:37:20 3000000007
1:2 3
255 max 05/01/2010 01:43:55 06/27/2010 22:37:23 3000000008
1:3 3
100 61234 05/01/2010 01:43:57 06/27/2010 22:37:26 3000000009
1:4 3
255 max 05/01/2010 01:43:59 06/27/2010 22:37:29 3000000010
1:5 3
100 61234 05/01/2010 01:44:01 06/27/2010 22:37:32 3000000011
-------------------------------------------------------------------------------
5 SDP('s) found
===============================================================================
show system security cpu-protection excessive-sources
===============================================================================
SAP's where the protection policy per-source rate limit is exceeded
===============================================================================
SAP-Id Service-Id
Plcy Limit
-------------------------------------------------------------------------------
1/1/1 3
100 65534
-------------------------------------------------------------------------------
1 SAP('s) found
===============================================================================
SDP's where the protection policy per-source rate limit is exceeded
===============================================================================
SDP-Id Service-Id Plcy Limit
-------------------------------------------------------------------------------
1:3 3 100 65534
1:4 3 255 max
1:5 3 100 65534
-------------------------------------------------------------------------------
3 SDP('s) found
===============================================================================
show system security cpu-protection policy association
===============================================================================
Associations for CPU Protection policy 100
===============================================================================
Description : (Not Specified)
SAP associations
-------------------------------------------------------------------------------
Service Id : 3 Type : VPLS
SAP 1/1/1 mac-monitoring
SAP 1/1/2 eth-cfm-monitoring aggr car
SAP 1/1/3 eth-cfm-monitoring
SAP 1/1/4
-------------------------------------------------------------------------------
Number of SAP's : 4
SDP associations
-------------------------------------------------------------------------------
Service Id : 3 Type : VPLS
SDP 1:1 eth-cfm-monitoring aggr car
SDP 1:3 eth-cfm-monitoring aggr
SDP 1:5 mac-monitoring
SDP 17407:4123456789 eth-cfm-monitoring car
-------------------------------------------------------------------------------
Number of SDP's : 4
Interface associations
-------------------------------------------------------------------------------
None
Managed SAP associations
-------------------------------------------------------------------------------
None
Video-Interface associations
-------------------------------------------------------------------------------
None
===============================================================================
Associations for CPU Protection policy 254
===============================================================================
Description : Default (Modifiable) CPU-Protection Policy assigned to Access
Interfaces
SAP associations
-------------------------------------------------------------------------------
None
SDP associations
-------------------------------------------------------------------------------
None
Interface associations
-------------------------------------------------------------------------------
Router-Name : Base
ies6If
Router-Name : vprn7
vprn7If
-------------------------------------------------------------------------------
Number of interfaces : 2
Managed SAP associations
-------------------------------------------------------------------------------
None
Video-Interface associations
-------------------------------------------------------------------------------
None
===============================================================================
Associations for CPU Protection policy 255
===============================================================================
Description : Default (Modifiable) CPU-Protection Policy assigned to Network
Interfaces
SAP associations
-------------------------------------------------------------------------------
None
SDP associations
-------------------------------------------------------------------------------
Service Id : 3 Type : VPLS
SDP 1:2
SDP 1:4 eth-cfm-monitoring
Service Id : 6 Type : IES
SDP 1:6
Service Id : 7 Type : VPRN
SDP 1:7
Service Id : 9 Type : Epipe
SDP 1:9
Service Id : 300 Type : VPLS
SDP 1:300
-------------------------------------------------------------------------------
Number of SDP's : 6
Interface associations
-------------------------------------------------------------------------------
Router-Name : Base
system
-------------------------------------------------------------------------------
Number of interfaces : 1
Managed SAP associations
-------------------------------------------------------------------------------
None
Video-Interface associations
-------------------------------------------------------------------------------
None
===============================================================================
show system security cpu-protection policy 100 association
===============================================================================
Associations for CPU Protection policy 100
===============================================================================
Description : (Not Specified)
SAP associations
-------------------------------------------------------------------------------
Service Id : 3 Type : VPLS
SAP 1/1/1 mac-monitoring
SAP 1/1/2 eth-cfm-monitoring aggr car
SAP 1/1/3 eth-cfm-monitoring
SAP 1/1/4
-------------------------------------------------------------------------------
Number of SAP's : 4
SDP associations
-------------------------------------------------------------------------------
Service Id : 3 Type : VPLS
SDP 1:1 eth-cfm-monitoring aggr car
SDP 1:3 eth-cfm-monitoring aggr
SDP 1:5 mac-monitoring
SDP 17407:4123456789 eth-cfm-monitoring car
-------------------------------------------------------------------------------
Number of SDP's : 4
Interface associations
-------------------------------------------------------------------------------
None
Managed SAP associations
-------------------------------------------------------------------------------
None
Video-Interface associations
-------------------------------------------------------------------------------
None
===============================================================================
A:bksim130#
show system security cpu-protection violators
==============================================================================
Ports where a rate limit is violated
===============================================================================
Port-Id
Type Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
No ports found
===============================================================================
===============================================================================
Interfaces where the protection policy overall rate limit is violated
===============================================================================
Interface-Name Router-Name
Plcy Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
No interfaces found
===============================================================================
===============================================================================
SAP's where the protection policy overall rate limit is violated
===============================================================================
SAP-Id Service-Id
Plcy Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
1/1/1 3
100 61234 05/01/2010 01:43:41 06/27/2010 22:37:02 3000000001
-------------------------------------------------------------------------------
1 SAP('s) found
===============================================================================
===============================================================================
SDP's where the protection policy overall rate limit is violated
===============================================================================
SDP-Id Service-Id
Plcy Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
1:1 3
100 61234 05/01/2010 01:43:41 06/27/2010 22:37:02 3000000001
1:2 3
255 max 05/01/2010 01:43:43 06/27/2010 22:37:05 3000000002
1:3 3
100 61234 05/01/2010 01:43:45 06/27/2010 22:37:08 3000000003
1:4 3
255 max 05/01/2010 01:43:47 06/27/2010 22:37:11 3000000004
1:5 3
100 61234 05/01/2010 01:43:49 06/27/2010 22:37:14 3000000005
-------------------------------------------------------------------------------
5 SDP('s) found
===============================================================================
===============================================================================
Video clients where the protection policy per-source rate limit is violated
===============================================================================
Client IP Address Video-Interface Service-Id
Plcy Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
No clients found
===============================================================================
eth-cfm-monitoring [{service-id
service-id sap-id
sap-id} | {service-id
service-id sdp-id
sdp-id:vc-id}]
*A:nodeA# show card 1 fp 1 dist-cpu-protection
===============================================================================
Card : 1 Forwarding Plane(FP) : 1
===============================================================================
Dynamic Enforcement Policer Pool : 2000
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
Statistics Information
-------------------------------------------------------------------------------
Dynamic-Policers Currently In Use : 48
Hi-WaterMark Hit Count : 72
Hi-WaterMark Hit Time : 01/03/2013 15:08:42 UTC
Dynamic-Policers Allocation Fail Count : 0
-------------------------------------------------------------------------------
===============================================================================
*A:nodeA# show service id 33 sap 1/1/3:33 dist-cpu-protection detail
===============================================================================
Service Access Points(SAP) 1/1/3:33
===============================================================================
Distributed CPU Protection Policy : test1
-------------------------------------------------------------------------------
Statistics/Policer-State Information
===============================================================================
-------------------------------------------------------------------------------
Static Policer
-------------------------------------------------------------------------------
Policer-Name : arp
Card/FP : 1/1 Policer-State : Conform
Protocols Mapped : arp
Exceed-Count : 0
Detec. Time Remain : 0 seconds Hold-Down Remain. : none
Operational (adapted) rate parameters:
Oper. Packets : 5 ppi Oper. Within : 8 seconds
Oper. Initial Delay: 6 packets
Oper. Depth : 0 packets
Policer-Name : dhcp
Card/FP : 1/1 Policer-State : Conform
Protocols Mapped : dhcp
Exceed-Count : 0
Detec. Time Remain : 0 seconds Hold-Down Remain. : none
Operational (adapted) rate parameters:
Oper. Kbps : 2343 kbps Oper. MBS : 240 kilobytes
Oper. Depth : 0 bytes
… (snip)
*A:nodaA# show service id 33 sap 1/1/3:34 dist-cpu-protection detail
===============================================================================
Service Access Points(SAP) 1/1/3:34
===============================================================================
Distributed CPU Protection Policy : test2
-------------------------------------------------------------------------------
Statistics/Policer-State Information
===============================================================================
-------------------------------------------------------------------------------
Static Policer
-------------------------------------------------------------------------------
No entries found
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
Local-Monitoring Policer
-------------------------------------------------------------------------------
Policer-Name : my-local-mon1
Card/FP : 1/1 Policer-State : conform
Protocols Mapped : arp, pppoe-pppoa
Exceed-Count : 0
All Dyn-Plcr Alloc. : False
Operational (adapted) rate parameters:
Oper. Packets : 10 ppi Oper. Within : 8 seconds
Oper. Initial Delay: 8 packets
Oper. Depth : 0 packets
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
Dynamic-Policer (Protocol)
-------------------------------------------------------------------------------
Protocol(Dyn-Plcr) : arp
Card/FP : 1/1 Protocol-State : not-applicable
Exceed-Count : 0
Detec. Time Remain : 0 seconds Hold-Down Remain. : none
Dyn-Policer Alloc. : False
Operational (adapted) rate parameters: unknown
Protocol(Dyn-Plcr) : pppoe-pppoa
Card/FP : 1/1 Protocol-State : not-applicable
Exceed-Count : 0
Detec. Time Remain : 0 seconds Hold-Down Remain. : none
Dyn-Policer Alloc. : False
Operational (adapted) rate parameters: unknown
-------------------------------------------------------------------------------
*A:Dut-A# show router interface "test" dist-cpu-protection detail
===============================================================================
Interface "test" (Router: Base)
===============================================================================
Distributed CPU Protection Policy : dcpuPol
-------------------------------------------------------------------------------
Statistics/Policer-State Information
===============================================================================
-------------------------------------------------------------------------------
Static Policer
-------------------------------------------------------------------------------
Policer-Name : staticArpPolicer
Card/FP : 4/1 Policer-State : Exceed
Protocols Mapped : arp
Exceed-Count : 10275218
Detec. Time Remain : 29 seconds Hold-Down Remain. : none
Operational (adapted) Rate Parameters:
Oper. Packets : 100 ppi Oper. Within : 1 seconds
Oper. Initial Delay: none
Oper. Depth : 100 packets
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
Local-Monitoring Policer
-------------------------------------------------------------------------------
Policer-Name : localMonitor
Card/FP : 4/1 Policer-State : Exceed
Protocols Mapped : icmp, ospf
Exceed-Count : 8019857
All Dyn-Plcr Alloc. : True
Operational (adapted) Rate Parameters:
Oper. Packets : 200 ppi Oper. Within : 1 seconds
Oper. Initial Delay: none
Oper. Depth : 0 packets
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
Dynamic-Policer (Protocol)
-------------------------------------------------------------------------------
Protocol(Dyn-Plcr) : icmp
Card/FP : 4/1 Protocol-State : Exceed
Exceed-Count : 1948137
Detec. Time Remain : 29 seconds Hold-Down Remain. : none
Dyn-Policer Alloc. : True
Operational (adapted) Rate Parameters:
Oper. Kbps : 25 kbps Oper. MBS : 256 bytes
Oper. Depth : 274 bytes
Protocol(Dyn-Plcr) : ospf
Card/FP : 4/1 Protocol-State : Exceed
Exceed-Count : 1487737
Detec. Time Remain : 29 seconds Hold-Down Remain. : none
Dyn-Policer Alloc. : True
Operational (adapted) Rate Parameters:
Oper. Kbps : 25 kbps Oper. MBS : 256 bytes
Oper. Depth : 284 bytes
-------------------------------------------------------------------------------
===============================================================================
policy [policy-id] association
violators [port
] [interface
] [sap
] [video
] [sdp
]
*A:SecuritySR7>config>sys>security>cpu-protection>policy# show system security cpu-protection violators
===============================================================================
Ports where a rate limit is violated
===============================================================================
Port-Id
Type Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
No ports found
===============================================================================
===============================================================================
Interfaces where the protection policy overall rate limit is violated
===============================================================================
Interface-Name Router-Name
Plcy Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
toIxia Base
255 1000 10/02/2012 18:38:23 10/02/2012 18:39:31 70
-------------------------------------------------------------------------------
1 interface(s) found
===============================================================================
===============================================================================
SAP's where the protection policy overall rate limit is violated
===============================================================================
SAP-Id Service-Id
Plcy Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
No SAP's found
===============================================================================
===============================================================================
SDP's where the protection policy overall rate limit is violated
===============================================================================
SDP-Id Service-Id
Plcy Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
No SDP's found
===============================================================================
===============================================================================
Video clients where the protection policy per-source rate limit is violated
===============================================================================
Client IP Address Video-Interface Service-Id
Plcy Limit First-Time Last-Time Violation-Periods
-------------------------------------------------------------------------------
No clients found
===============================================================================
*B:bksim67# show system security cpm-filter mac-filter
===============================================================================
CPM Mac Filter (applied)
===============================================================================
Entry-Id Dropped Forwarded Description
-------------------------------------------------------------------------------
1 23002 47094
-------------------------------------------------------------------------------
Num CPM Mac filter entries: 1
===============================================================================
*B:bksim67#
*B:bksim67# show system security management-access-filter mac-filter
=============================================================================
Mac Management Access Filter
=============================================================================
filter type : mac
Def. Action : permit
Admin Status : enabled (no shutdown)
-------------------------------------------------------------------------------
Entry : 1 Action : deny
FrameType : ethernet_II Svc-Id : Undefined
Src Mac : Undefined
Dest Mac : Undefined
Dot1p : Undefined Ethertype : Disabled
DSAP : Undefined SSAP : Undefined
Snap-pid : Undefined ESnap-oui-zero : Undefined
cfm-opcode : Undefined
Log : disabled Matches : 0
=============================================================================
*B:bksim67#
*A:ALA-A# show system security keychain test
===============================================================================
Key chain:test
===============================================================================
TCP-Option number send : 254 Admin state : Up
TCP-Option number receive : 254 Oper state : Up
===============================================================================
*A:ALA-A#
*A:ALA-A# show system security keychain test detail
===============================================================================
Key chain:test
===============================================================================
TCP-Option number send : 254 Admin state : Up
TCP-Option number receive : 254 Oper state : Up
===============================================================================
Key entries for key chain: test
===============================================================================
Id : 0
Direction : send-receive Algorithm : hmac-sha-1-96
Admin State : Up Valid : Yes
Active : Yes Tolerance : 300
Begin Time : 2007/02/15 18:28:37 Begin Time (UTC) : 2007/02/15 17:28:37
End Time : N/A End Time (UTC) : N/A
===============================================================================
Id : 1
Direction : send-receive Algorithm : aes-128-cmac-96
Admin State : Up Valid : Yes
Active : No Tolerance : 300
Begin Time : 2007/02/15 18:27:57 Begin Time (UTC) : 2007/02/15 17:27:57
End Time : 2007/02/15 18:28:13 End Time (UTC) : 2007/02/15 17:28:13
===============================================================================
Id : 2
Direction : send-receive Algorithm : aes-128-cmac-96
Admin State : Up Valid : Yes
Active : No Tolerance : 500
Begin Time : 2007/02/15 18:28:13 Begin Time (UTC) : 2007/02/15 17:28:13
End Time : 2007/02/15 18:28:37 End Time (UTC) : 2007/02/15 17:28:37
===============================================================================
*A:ALA-A#
*A:Dut-F# show system security management-access-filter ip-filter
=============================================================================
IPv4 Management Access Filter
=============================================================================
filter type: : ip
Def. Action : permit
Admin Status : enabled (no shutdown)
-----------------------------------------------------------------------------
Entry : 1
Src IP : 192.168.0.0/16
Src interface : undefined
Dest port : undefined
Protocol : undefined
Router : undefined
Action : none
Log : disabled
Matches : 0
=============================================================================
*A:Dut-F#
*A:Dut-C# show system security management-access-filter ipv6-filter entry 1
=============================================================================
IPv6 Management Access Filter
=============================================================================
filter type : ipv6
Def. Action : permit
Admin Status : enabled (no shutdown)
-----------------------------------------------------------------------------
Entry : 1
Src IP : 2001::1/128
Flow label : undefined
Src interface : undefined
Dest port : undefined
Next-header : undefined
Router : undefined
Action : permit
Log : enabled
Matches : 0
=============================================================================
*A:Dut-C# s
A:ALA-7# show system security password-options
===============================================================================
Password Options
===============================================================================
Password aging in days : none
Time required between password changes : 0d 00:10:00
Number of invalid attempts permitted per login : 3
Time in minutes per login attempt : 5
Lockout period (when threshold breached) : 10
Authentication order : radius tacplus local
User password history length : disabled
Accepted password length : 6..56 characters
Credits for each character type : none
Required character types : none
Minimum number different character types : 0
Required distance with previous password : 5
Allow consecutively repeating a character : always
Allow passwords containing username : yes
Palindrome allowed : no
===============================================================================
A:ALA-7#
A:ALA-48# show system security per-peer-queuing
=================================================
CPM Hardware Queuing
=================================================
Per Peer Queuing : Enabled
Total Num of Queues : 8192
Num of Queues In Use : 2
=================================================
A:ALA-48# configure
If the profile-name is not specified, then information for all profiles are displayed.
A:ALA-7# show system security profile administrative
===============================================================================
User Profile
===============================================================================
User Profile : administrative
Def. Action : permit-all
-------------------------------------------------------------------------------
Entry : 10
Description :
Match Command: configure system security
Action : permit
-------------------------------------------------------------------------------
Entry : 20
Description :
Match Command: show system security
Action : permit
-------------------------------------------------------------------------------
No. of profiles:
===============================================================================
A:ALA-7#
A:SR-7# show system security source-address
===============================================================================
Source-Address applications
===============================================================================
Application IP address/Interface Name Oper status
-------------------------------------------------------------------------------
telnet 10.20.1.7 Up
radius loopback1 Up
===============================================================================
A:SR-7#
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
des — Data encryption using a private (secret) key.
3des — An encryption method that allows proprietary information to be transmitted over untrusted networks.
|
|
|
|
|
|
|
|
|
*A:ALA-49# show system security ssh
===============================================================================
SSH Server
===============================================================================
Administrative State : Enabled
Operational State : Up
Preserve Key : Enabled
SSH Protocol Version 1 : Disabled
SSH Protocol Version 2 : Enabled
DSA Host Key Fingerprint : 88:41:1c:7e:97:64:df:a0:e4:54:c2:cc:3d:dd:c7:70
RSA Host Key Fingerprint : 63:b8:c4:8a:17:b7:1c:95:35:91:c9:08:75:cc:31:a3
-------------------------------------------------------------------------------
Connection Username Version ServerName Status
-------------------------------------------------------------------------------
138.120.214.254 admin 2 netconf connected
138.120.140.148 admin 2 cli connected
-------------------------------------------------------------------------------
Number of SSH sessions : 2
===============================================================================
*A:Dut-C# show system security user detail
===============================================================================
Users
===============================================================================
User ID New User Permissions Password Login Failed Local
Pwd console ftp li snmp Expires Attempts Logins Conf
-------------------------------------------------------------------------------
admin n y n n n never 4 0 y
-------------------------------------------------------------------------------
Number of users : 1
===============================================================================
*A:Dut-C# show system security user detail
===============================================================================
User Configuration Detail
===============================================================================
===============================================================================
user id : admin
-------------------------------------------------------------------------------
console parameters
-------------------------------------------------------------------------------
new pw required : no cannot change pw : no
home directory :
restricted to home : no
login exec file :
profile : administrative
locked-out : yes (9:23 remaining)
-------------------------------------------------------------------------------
snmp parameters
-------------------------------------------------------------------------------
===============================================================================
*A:Node234# show system security user lockout
===============================================================================
Currently Failed Login Attempts
===============================================================================
User ID Remaining Login attempts Remaining Lockout Time (min:sec)
-------------------------------------------------------------------------------
jason123 N/A 9:56
-------------------------------------------------------------------------------
Number of users : 1
===============================================================================
All client authentications are logged and display in the show>system>security>user detail.
Table 26 shows the rules where pass and fail attempts are logged.
TABLE
*A:Dut-C# show system security user detail
===============================================================================
Users
===============================================================================
User ID New User Permissions Password Login Failed Local
Pwd console ftp li snmp Expires Attempts Logins Conf
-------------------------------------------------------------------------------
admin n y n n n never 4 0 y
-------------------------------------------------------------------------------
Number of users : 1
===============================================================================
===============================================================================
User Configuration Detail
===============================================================================
===============================================================================
user id : admin
-------------------------------------------------------------------------------
console parameters
-------------------------------------------------------------------------------
new pw required : no cannot change pw : no
home directory :
restricted to home : no
login exec file :
profile : administrative
-------------------------------------------------------------------------------
snmp parameters
-------------------------------------------------------------------------------
===============================================================================
view [view-name] [detail
]
A:ALA-48# show system security view
===============================================================================
Views
===============================================================================
view name oid tree mask permission
-------------------------------------------------------------------------------
iso 1 included
read1 1.1.1.1 11111111 included
write1 2.2.2.2 11111111 included
testview 1 11111111 included
testview 1.3.6.1.2 11111111 excluded
mgmt-view 1.3.6.1.2.1.2 included
mgmt-view 1.3.6.1.2.1.4 included
mgmt-view 1.3.6.1.2.1.5 included
mgmt-view 1.3.6.1.2.1.6 included
mgmt-view 1.3.6.1.2.1.7 included
mgmt-view 1.3.6.1.2.1.31 included
mgmt-view 1.3.6.1.2.1.77 included
mgmt-view 1.3.6.1.4.1.6527.3.1.2.3.7 included
mgmt-view 1.3.6.1.4.1.6527.3.1.2.3.11 included
vprn-view 1.3.6.1.2.1.2 included
vprn-view 1.3.6.1.2.1.4 included
vprn-view 1.3.6.1.2.1.5 included
vprn-view 1.3.6.1.2.1.6 included
vprn-view 1.3.6.1.2.1.7 included
vprn-view 1.3.6.1.2.1.15 included
vprn-view 1.3.6.1.2.1.23 included
vprn-view 1.3.6.1.2.1.31 included
vprn-view 1.3.6.1.2.1.68 included
vprn-view 1.3.6.1.2.1.77 included
vprn-view 1.3.6.1.4.1.6527.3.1.2.3.7 included
vprn-view 1.3.6.1.4.1.6527.3.1.2.3.11 included
vprn-view 1.3.6.1.4.1.6527.3.1.2.20.1 included
no-security 1 included
no-security 1.3.6.1.6.3 excluded
no-security 1.3.6.1.6.3.10.2.1 included
no-security 1.3.6.1.6.3.11.2.1 included
no-security 1.3.6.1.6.3.15.1.1 included
on-security 2 00000000 included
-------------------------------------------------------------------------------
No. of Views: 33
===============================================================================
A:ALA-48#
A:ALA-7# show users
===============================================================================
User Type From Login time Idle time
===============================================================================
testuser Console -- 21FEB2007 04:58:55 0d 00:00:00 A
-------------------------------------------------------------------------------
Number of users : 1
'A' indicates user is in admin mode
===============================================================================
A:ALA-7#
The no form of the command disables the debugging.
The no form of the command disables the debug output.
[no
] ca-profile
profile-name
Values
|
1— n (n is platform dependant)
|
*A:Dut-A# tools dump security dist-cpu-protection violators enforcement interface card 4 fp 1
===============================================================================
Distributed Cpu Protection Current Interface Enforcer Policer Violators
===============================================================================
Interface Policer/Protocol Hld Rem
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
Violators on Slot-4 Fp-1
-------------------------------------------------------------------------------
test staticArpPolicer [S] none
test icmp [D] none
test ospf [D] none
-------------------------------------------------------------------------------
[S]-Static [D]-Dynamic [M]-Monitor
-------------------------------------------------------------------------------
===============================================================================