Cisco Traffic Anomaly Detector Module Web-Based Manager Configuration Guide (Software Version 5.0)
Preface

Table Of Contents

Preface

Audience

Organization

Conventions

Obtaining Documentation, Obtaining Support, and Security Guidelines


Preface


The Cisco Traffic Anomaly Detector Module Web-Based Manager Configuration Guide describes the Web-based Manager (WBM), a graphical user interface (GUI) for remotely operating the Detector module and monitoring the Detector module activity, status, and statistics. The WBM communicates with the Detector module by translating its HTML pages into Detector module commands. These are the same commands that you can enter using the command-line interface (CLI). This guide describes the WBM workflow and operation.

Some features of the Detector module, mostly related to the initial installation and configuration of the Detector module, can only be configured using the CLI and cannot be configured using the WBM. Refer to the Cisco Traffic Anomaly Detector Module Configuration Guide for details on using the CLI.

This preface contains the following major sections:

Audience

Organization

Conventions

Obtaining Documentation, Obtaining Support, and Security Guidelines

Audience

This guide is intended for the following trained and qualified personnel who are responsible for operating the WBM:

· System administrator

· System operator

Organization

This user guide is divided into the following chapters:

Chapter
Description

Chapter 1, "Introduction"

Provides information on system requirements and an overview of the Detector module and the WBM.

Chapter 2, "Enabling and Launching the WBM"

Provides an overview of the basic WBM procedures and explains on how to set up and connect to the Detector module WBM.

Chapter 3, "Managing User Access"

Describes how to use the WBM to create, modify, and delete the user profiles that control access to the Detector module WBM.

Chapter 4, "Creating and Configuring Zones"

Describes how to create and manage the Detector module zones.

Chapter 5, "Configuring Zone Filters"

Describes how to perform advanced zone filter configuration tasks on the Detector module.

Chapter 6, "Configuring Policy Templates"

Describes how to perform advanced policy template configuration tasks on the Detector module.

Chapter 7, "Learning Zone Traffic"

Describes how to use the Detector module learning process to analyze zone traffic and create zone-specific policies.

Chapter 8, "Managing Zone Policies"

Describes how to manage zone policies.

Chapter 9, "Activating Anomaly Detection"

Describes how to perform tasks associated with detecting zone traffic anomalies and DDoS attacks.

Chapter 10, "Monitoring Detector Module and Zone Operations"

Describes how to perform tasks used for monitoring Detector module zones and displaying zone statistics and diagnostic information.

Chapter 11, "Managing the Packet-Dump Feature"

Describes how to initiate the packet-dump capture feature and view the packet-dump capture contents.


Conventions

This manual uses the following conventions:

Convention
Description

boldface font

Indicates commands and keywords.

Italic font

Indicates arguments and refers the reader to places in the document for further details.

Screen font

Information to be displayed or typed on the screen.

Braces ({ })

Indicates command parameters from which you must choose one.

Square brackets ([ ])

Indicates an optional command parameter.

admin@DETECTOR#

Indicates the default CLI prompt.


Notes use the following conventions:


Note Means reader take note. Notes contain helpful suggestions or references to material not covered in the user guide.


Cautions use the following conventions:


Caution Means reader be careful. In this situation, you might do something that could result in equipment damage or loss of data.

Tips use the following conventions:


Tip Means the following information will help you solve a problem. The tips information might not be troubleshooting or even an action, but could be useful information.


Obtaining Documentation, Obtaining Support, and Security Guidelines

For information on obtaining documentation, obtaining support, providing documentation feedback, security guidelines, and also recommended aliases and general Cisco documents, see the monthly What's New in Cisco Product Documentation, which also lists all new and revised Cisco technical documentation, at:

http://www.cisco.com/en/US/docs/general/whatsnew/whatsnew.html