Enhancements

Release M.10.04 Enhancements

ProCurve# show sflow sampling-polling 1-5

sflow destination Enabled

Port

Sampling

Rate

Header

Dropped

Polling

Interval

----- +

Enabled

Samples

Enabled

-------

--------

------

---------- +

------- --------

1

Yes

6500000

128

5671234

 

Yes

60

2

No

50

128

0

 

Yes

300

3

Yes

2000

100

24978

 

No

30

4

Yes

200

100

4294967200

 

Yes

40

5

Yes

20000

128

34

 

Yes

500

Figure 15. Example of Viewing sFlow Sampling and Polling Information

The show sflow all command combines the outputs of the preceding three show commands including sFlow status information for all the ports on the switch.

Release M.10.04 Enhancements

Release M.10.04 includes the following enhancements:

Enhancement (PR_1000330743) - Instrumentation Monitor, which includes Denial of Service (DoS) logging enhancement.

Enhancement (PR_1000331027) - TCP/UDP port closure enhancement.

Enhancement (PR_1000330532) - Improved the "show" command display of STP port detail information to assist in monitoring and troubleshooting of the spanning tree protocol.

Instrumentation Monitor

The 3400cl switches have instrumentation to monitor many operating parameters at pre-determined intervals. Beginning with software release M.10.04, this capability can be used to detect anomalies caused by security attacks or other irregular operations on the switch. The following table shows the parameters that can be monitored, and the possible security attacks that may trigger an alert:

Parameter Name

Description

pkts-to-closed-ports

The count of packets per minute sent to closed TCP/UDP ports. An excessive amount

 

of packets could indicate a port scan, in which an attacker is attempting to expose a

 

vulnerability in the switch.

arp-requests

The count of ARP requests processed per minute. A large amount of ARP request

 

packets could indicate an host infected with a virus that is trying to spead itself.

70