Configuring Attack Source Tracing; Establishing The Configuration Task - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

6 Local Attack Defense Configuration
Related slot : <4>
Configuration :
Run the display cpu-defend tcp statistics slot 4 to view statistics about TCP packets directing
at the CPU.
<Quidway> display cpu-defend tcp statistics slot 4
CPCAR on slot 4
-------------------------------------------------------------------------------
Packet Type
tcp
-------------------------------------------------------------------------------

6.4 Configuring Attack Source Tracing

After the attack source tracing function is configured, the system can actively defend against
possible attack packets by analyzing whether packets directing at the CPU attack the CPU.

6.4.1 Establishing the Configuration Task

6.4.2 Creating an Attack Defense Policy
6.4.3 Enabling the Automatic Attack Source Tracing
6.4.4 Configuring the Threshold of Attack Source Tracing
6.4.5 (Optional) Configuring the Attack Source Alarm Function
6.4.6 Applying the Attack Defense Policy
6.4.7 Checking the Configuration
6.4.1 Establishing the Configuration Task
Applicable Environment
A large number of attack packets may attack the CPUs of devices on the network. Attack source
tracing, as a means of proactive attack defense, actively defend against possible attack packets
by analyzing whether packets directing at the CPU may attack the CPU.
Pre-configuration Tasks
Before configuring attack source tracing, complete the following task.
l
l
6-8
Car user-defined-flow 1 : CIR(64)
Car user-defined-flow 2 : CIR(64)
Car user-defined-flow 3 : CIR(64)
Car user-defined-flow 4 : CIR(64)
Car user-defined-flow 5 : CIR(64)
Car user-defined-flow 6 : CIR(64)
Car user-defined-flow 7 : CIR(64)
Car user-defined-flow 8 : CIR(64)
Pass(Bytes)
Connecting interfaces and setting the physical parameters of each interface to make the
physical layer in Up state
(Optional) If the attack defense policy needs to be applied to the main control board, install
a flexible service unit to the main control board.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
CBS(10000)
CBS(10000)
CBS(10000)
CBS(10000)
CBS(10000)
CBS(10000)
CBS(10000)
CBS(10000)
Drop(Bytes)
Pass(Packets)
0
0
Configuration Guide - Security
Drop(Packets)
0
0
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents