Cisco Systems OL-6109-01 manual Learning Phase 2 Threshold Tuning

Page 16

Chapter 4 Zone Configuration

Zone Traffic Learning

Note that the Detector enables the use of an asterisk (*) as a wildcard denoting either of the following options:

All of the Detector’s zones. Issuing no learning* reject means aborting the learning phase for all of the Detector’s zones.

A wildcard denoting zone names (i.e. OBL*).

2.Choose ENTER.

Learning Phase 2 – Threshold Tuning

During this stage the Detector constructs its detection policies and begins to tune its traffic type thresholds (see Chapter 7, “Policy Procedures” for further details).

To begin the second Learning phase perform the following:

1.From the Global command group level type the following:

admin@DETECTOR# learning threshold-tuning <zone-name>

Or alternatively:

From the zone command group level type the following:

admin@DETECTOR-conf-zone-<zone-name># learning threshold-tuning

Where zone-namespecifies a zone name.

Note that the Detector enables the use of an asterisk (*) as a wildcard denoting either of the following options:

All of the Detector’s zones. Issuing learning threshold-tuning*means setting the threshold tuning phase for all of the Detector’s zones.

A wildcard denoting zone names (i.e. OBL*).

2.Choose ENTER.

Note Cisco Systems recommends letting the Learning Phase 2 - Threshold Tuning continue for 24 hours before concluding.

 

Cisco Traffic Anomaly Detector User Guide

4-16

OL-6109-01

Image 16
Contents Zone Configuration Basic Zone ConfigurationDefining a New Zone Duplicating a Zone Removing a Zone Removing All Zones Displaying Zone TemplatesEntering a Zone Command Level Describing a Zone Defining the Zone IP AddressRemoving a Zone IP Address Zone Remote Guard List Removing all Zone IP AddressesAdding a Guard to the Zone Remote Guard List Removing a Guard from the Zone Remote Guard ListInteractive Recommendations Mode Activating the Interactive Recommendation ModeDeactivating the Interactive Recommendation Mode Zone Traffic Learning Learning Phase 1 Policy Construction Terminating Learning Phase 1 -Policy Construction Accepting Learning Phase 1 Policy Construction Aborting Learning Phase 1 Policy ConstructionLearning Phase 2 Threshold Tuning Terminating Learning Phase 2 Threshold Tuning Accepting Learning Phase 2 Threshold TuningLearning Phase Verification Aborting Learning Phase 2 Tuning ThresholdZone Detection Choose ENTER. The following partial sample screen appearsGuard-Protection Activation Forms Zone Detection Verification Ending the Zone Detection