Cisco DDoS Multi-Device Management System Configuration Guide (Software Release 1.5)
Preface

Table Of Contents

Preface

Audience

Organization

Related Documentation

Conventions

Obtaining Documentation, Obtaining Support, and Security Guidelines


Preface


This preface describes the audience, organization, and conventions of this publication, and provides information on how to obtain related documentation.

This preface contains the following sections:

Audience

Organization

Related Documentation

Conventions

Obtaining Documentation, Obtaining Support, and Security Guidelines

Audience

The Cisco DDoS MultiDevice Manager Configuration Guide is intended primarily for the following audiences:

Network administrators

Engineers

Operators

Network security professionals

This guide assumes a thorough knowledge of networking and networking security.

Organization

This guide is organized as follows:

Chapter
Description

Chapter 1, "Product Overview"

Describes the Cisco DDoS MultiDevice Manager (MDM), the MDM operation states, and the MDM network components.

Chapter 2, "Getting Started"

Describes how to install, launch, and log in to the MDM. The chapter also describes the MDM interface.

Chapter 3, "Managing Devices on the MDM Network"

Describes how to define and manage devices on the MDM network.

Chapter 4, "Resolving Conflicts and Synchronizing Zones"

Describes how to verify the synchronization status of zones, resolve conflicts, and synchronize zones.

Chapter 5, "Creating and Configuring Zones"

Describes how to create and manage zones.

Chapter 6, "Managing Zone Filters"

Describes how to configure the zone filters.

Chapter 7, "Managing Zone Policy Templates"

Describes how to configure the zone policy templates.

Chapter 8, "Managing Zone Policies"

Describes how to configure and manage the zone policies.

Chapter 9, "Learning Zone Traffic and Taking Snapshots"

Describes how to activate the learning process to construct and adjust the policies that the Detectors use to detect anomalies in the zone traffic and that the Guards use for zone protection.

Chapter 10, "Activating Anomaly Detection and Zone Protection"

Describes how to activate zones. The chapter outlines how to activate the Detectors to detect anomalies in the zone traffic and how to activate the Guards to protect the zone.

Chapter 11, "Monitoring Zone and Device Operations"

Describes how to monitor devices by using the device counters and the event log, monitor zones by using the zone counters, event log, and statistics, and use attack reports to monitor past and ongoing attacks.

Chapter 12, "Troubleshooting Problems with the MDM"

Describes how to troubleshoot error conditions that are associated with operating the MDM.


Related Documentation

In addition to this guide, the Detector and Guard documentation set includes the following documents:

Document Title
Description

Cisco Guard Configuration Guide

Provides information for configuring the Guard appliance using the CLI.

Cisco Anomaly Guard Module
Configuration Guide

Provides information for configuring the Guard module for use in the Catalyst 6500 series switch or Cisco 7600 series router using the CLI.

Cisco Guard Web-Based Manager Configuration Guide

Provides information for configuring and managing the Guard appliance using the Web-Based Manager (WBM).

Cisco Anomaly Guard Module Web-Based Manager Configuration Guide

Provides information for configuring and managing the Guard module using the Web-Based Manager (WBM).

Cisco Traffic Anomaly Detector
Configuration Guide

Provides information for configuring the Detector appliance using the CLI.

Cisco Traffic Anomaly Detector Module Configuration Guide

Provides information for configuring the Detector module for use in the Catalyst 6500 series switch or Cisco 7600 series router using the CLI.

Cisco Traffic Anomaly Detector Web-Based Manager Configuration Guide

Provides information for managing the Detector appliance using the WBM.

Cisco Traffic Anomaly Detector Module Web-Based Manager
Configuration Guide

Provides information for configuring and managing the Detector module using the Web-Based Manager (WBM).


Conventions

This guide uses the following conventions:

Convention
Description

boldface font

Menu options, button names, and names of keys on the keyboard.

Italic font

Emphasize information, introduction of new significant terms, or titles of other documents that you should see as a reference.

Screen font

Screen font indicates information that the device CLI displays on the screen.

user#DEVICE#

CLI prompt.


This guide uses the following symbols and conventions to identify different types of information:


Note Means reader take note. Notes contain helpful suggestions or references to material not covered in the manual.



Caution Means reader be careful. In this situation, you might do something that could result in equipment damage or loss of data.


Tip Means the following information will help you solve a problem. The tips information might not be troubleshooting or even an action, but could be useful information.


Obtaining Documentation, Obtaining Support, and Security Guidelines

For information on obtaining documentation, obtaining support, providing documentation feedback, security guidelines, and also recommended aliases and general Cisco documents, see the monthly What's New in Cisco Product Documentation, which also lists all new and revised Cisco technical documentation, at:

http://www.cisco.com/en/US/docs/general/whatsnew/whatsnew.html