Configuring Cpu Attack Defense - Huawei AR1200-S Configuration Manual

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
2.
Step 10 In the system view, run:
cpu-defend-policy policy-name [ global | slot slot-id ]
The attack defense policy is applied.
If the attack defense policy is applied to an LPU or SRU, it takes effect for only the packets sent
to the CPU of the LPU or SRU.
If global or slot is not specified, the attack defense policy is applied to the SRU. If global is
specified, the attack defense policy is applied to all LPUs. If slot is specified, the attack defense
policy is applied to an LPU in a specified slot.
Attack source tracing configured in an attack defense policy takes effect only when the attack defense policy is
applied to the SRU.
----End
Checking the Configuration
# Run the display auto-defend attack-source command to view the attack source list on the
SRU.
# Run the display auto-defend configuration command to view the configuration of attack
source tracing.
# Run the display cpu-defend policy command to check the attack defense policy.

9.4 Configuring CPU Attack Defense

CPU attack defense limits the rate of packets sent to the CPU to protect the CPU.
9.4.1 Establishing the Configuration Task
Before configuring an attack defense policy, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the data required for the
configuration. This will help you complete the configuration task quickly and accurately.
Applicable Environment
When a large number of users connect to the AR1200-S, the AR1200-S may be attacked by the
packets sent to the CPU or needs to process a large of number of these packets. The AR1200-
S can limit the rate of all the packets sent to the CPU to protect the CPU.
CPU attack defense provides hierarchical device protection:
l
Issue 02 (2012-03-30)
(Optional) Run:
auto-defend alarm threshold threshold
The alarm threshold for attack source tracing is set.
By default, the alarm threshold for attack source tracing is 128 pps.
NOTE
Level 1: The AR1200-S uses blacklists to filter invalid packets sent to the CPU.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
9 Local Attack Defense Configuration
172

Advertisement

Table of Contents
loading

Table of Contents