Intrusion Detection/Intrusion Prevention System
Left running head:
Chapter name (automatic)
936
Beta Beta
OmniAccess 5740 Unified Services Gateway CLI Configuration Guide
Alcatel-Lucent
IDS/IPS DEBUG COMMANDS
This section lists the debug commands in IDS/IPS.
T
O ENABLE / DISABLE DEBUGGING ON FIREWALL
Notes: 1. saddr == source address
2. daddr == destination address
3. sport == source port
4. dport == destination port
EXAMPLE
ALU# debug firewall intrusion
ALU# no debug firewall intrusion
Command (in SUM/CM) Description
debug firewall {session|filter
|nat|attack|alg|intrusion|sele
ctor [saddr <ip-address>|daddr
<ip-address>|protocol
<number>|sport <number>|dport
<number>][output|permanent]|
all [detail-level]}
This command turns on the debugging
functionality for IDS/IPS on the
OmniAccess 5740 USG.
The “selector” keyword allows you to
debug only selected traffic.
no debug firewall
{session|filter|nat|attack|alg
|intrusion|selector [saddr
<ip-address>|daddr <ip-
address>|protocol <number> |
sport <number>|dport <number>]
[output|permanent]|all
[detail-level]}
Use this command to turn off the
debugging functionality for IDS/IPS.
The “selector” keyword allows you to
turn off debugging only for selected
traffic.