This section describes how to configure the Threat Management Service (TMS) applications.
Topics include:
TMS is only supported on the 7750 SR-7 and 7750 SR-12; it is not supported on the 7750 SR-a or 7750 SR-e. The ISA-TMS supports routed redirect mode on IOM3, which means that traffic based on destination IP address (under attack) is filtered (scrubbed) by a variety of DDoS filtering rules provided by 3rd party code from Arbor Networks.
When a DDoS attack is detected by the Arbor Networks CP (based on cflowd counters) a notification is send to the 7750 SR CPM. This is the trigger for the 7750 SR CPM to attract the traffic under attack via the advertisement of a route with prefix the destination IP address under attack and with next-hop the scrubber. This process is called off-ramping.
At that point all destination traffic to the IP address under attack is forwarded to the 7750 SR where:
The TMS images should be stored in the same location as the other images (cpm.tim, iom.tim, etc). This is to where the BOF points.
The name of the file is peakflow-tms.tim.
Follow the usage guidelines listed below:
The following requirement will enhance the performance and scale of DDoS protection via a tight integration between the Arbor TMS DDoS scrubbing application and the 7750 SR highly scalable IP filters.
The Arbor TMS application uses a wide variety of methods for identifying specific flows that are part of a network or application Denial of Service attack. These techniques include network and application behavior analysis as well as specific packet-based content detection.
Once a specific flow has been identified as part of the attack, one of the common methods of mitigation includes host-based (source-IP), IP blacklisting. Instead of continuing to analyze every packet of that flow up to Layer 7 analysis, based on the initial detection TMS will use IP host-based blacklisting to temporarily block traffic from that source toward the destination under attack.
This feature adds the ability to have the TMS application within the 7750 SR signal the 7750 SR through the ALU API controlling highly scalable IP filters for hardware-based, source-IP blacklisting in order to significantly enhance the scale and performance of the blacklisting function.
![]() | Note:
R6.0p4 or later of Arbor TMS is required to support this feature on the 7750 SR. |
This feature exemplifies how Arbor Networks and ALU continue to improve the overall DDoS detection and mitigation function.