show voip ids

This command displays the Intrusion Detection System (IDS) blacklist of remote hosts (IP addresses / ports) considered malicious.

Syntax

# show voip ids {blacklist active|active-alarm}
# show voip ids active-alarm {all|match <ID> rule <ID>}

Command

Description

active-alarm

Displays all active blacklist alarms:

■ all (Displays all active alarms)
■ match (Displays active alarms of an IDS matched ID and rule ID)

blacklist active

Displays blacklisted hosts.

Command Mode

Privileged User

Related Commands

■ ids policy
■ ids rule
■ clear voip ids blacklist

Example

■ Displaying the IDS blacklist:
# show voip ids blacklist active
Active blacklist entries:
10.33.5.110(NI:0) remaining 00h:00m:10s in blacklist

Where SI is the SIP Interface, and NI is the Network interface.

■ Displaying the blacklist of all active IDS alarms:
# show voip ids active-alarm all
IDSMatch#0/IDSRule#1: minor alarm active.
■ Displaying details regarding an active IDS alarm of the specified match and rule IDs:
# show voip ids active-alarm match 0 rule 1
IDSMatch#0/IDSRule#1: minor alarm active.
- Scope values crossed while this alarm is active:
    10.33.5.110(SI0)