Huawei AR1200-S Configuration Manual page 82

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
firewall defend all enable
All the attack defense functions are enabled.
Step 3 Run:
firewall defend fraggle enable
The Fraggle attack defense is enabled.
Step 4 Run:
firewall defend icmp-flood enable
The ICMP Flood attack defense is enabled.
After the parameters for ICMP Flood attack defense are set, you must enable the ICMP Flood
attack defense function; otherwise, the AR1200-S does not detect the attack packets or take
attack defense measures.
Step 5 Run:
firewall defend icmp-redirect enable
The ICMP Redirect attack defense is enabled.
Step 6 Run:
firewall defend icmp-unreachable enable
The ICMP Unreachable attack defense is enabled.
Step 7 Run:
firewall defend ip-fragment enable
The IP-Fragment attack defense is enabled.
Step 8 Run:
firewall defend ip-sweep enable
The IP address sweeping attack defense is enabled.
After the parameters for IP address sweeping attack defense are set, you must enable the IP
address sweeping attack defense function; otherwise, the AR1200-S does not detect the attack
packets or take attack defense measures.
Step 9 Run:
firewall defend land enable
The Land attack defense is enabled.
Step 10 Run:
firewall defend large-icmp enable
The large ICMP packet attack defense is enabled.
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 Firewall Configuration
68

Advertisement

Table of Contents
loading

Table of Contents