Huawei AR1200-S Configuration Manual page 307

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
l
l
Procedure
Step 1 Configure the IP addresses and routes of each interface to guarantee internetworking (omitted).
Step 2 Enable defense against abnormal packet attacks on Router A.
<RouterA> system-view
[RouterA] anti-attack abnormal enable
Step 3 # Enable defense against packet fragment attacks on Router A and restrict the rate for sending
fragments packet to 15000 bit/s.
[RouterA] anti-attack fragment enable
#
[RouterA] anti-attack fragment car cir 15000
Step 4 # Enable defense against SYN flood attacks on Router A and restrict the rate for sending TCP
SYN packets to 15000 bit/s.
[RouterA] anti-attack tcp-syn enable
[RouterA] anti-attack tcp-syn car cir 15000
# Enable defense against UDP flood attacks on Router A to discard the UDP packets sent on
specified ports.
[RouterA] anti-attack udp-flood enable
# Enable defense against ICMP flood attacks on Router A and restrict the rate for sending ICMP
flood packets to 15000 bit/s.
[RouterA] anti-attack icmp-flood enable
[RouterA] anti-attack icmp-flood car cir 15000
Step 5 Verify the configuration.
After the configuration is complete, run the display anti-attack statistics [ abnormal |
fragment | tcp-syn | udp-flood | icmp-flood ] command to check the statistics of packet attack
defense.
<RouterA> display anti-attck statistics
Packets Statistic Information:
-------------------------------------------------------------------------------
AntiAtkType
-------------------------------------------------------------------------------
URPF
Abnormal
Fragment
Tcp-syn
Udp-flood
Icmp-flood
-------------------------------------------------------------------------------
----End
Configuration Files
l
Issue 02 (2012-03-30)
IP address of each interface
Restricted rate of sending packets to the CPU
TotalPacketNum
(H)
(L)
0
0
0
0
0
0
Configuration file of Router A
#
sysname RouterA
#
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
14 Configuration of Attack Defense and Application Layer
DropPacketNum
(H)
0
0
0
0
0
0
30
0
0
0
40
0
PassPacketNum
(L)
(H)
0
0
0
0
0
0
0
0
0
0
0
0
Association
(L)
0
0
0
30
0
40
293

Advertisement

Table of Contents
loading

Table of Contents