cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
876
Views
0
Helpful
2
Replies

Monitor DoS attack on the router

rmrahman0302
Level 1
Level 1

Hi,

How to monitor DoS attack on the router? My router is getting aggressive and cutting down the session.

Thanks.

2 Replies 2

rstanisl
Cisco Employee
Cisco Employee

Hi,

One way to find out the traffic coming into or going out of the interface is to enable "ip route-cache flow" under the interface

show ip cache flow command will show you the source and destination interface info to help you track down a specific host that could be causing the issue.

it can be chatty if your cpu is very high i would not recommend.

hope this helps

Raymond

sfaizul
Level 1
Level 1

I agree with Raymond ,show ip cache flow command will show you the source and destination interface info to help you track down a specific host that could be causing the issue.

Then you can configure Control plane policy to limit the traffic to cpu.

Regards
syed.