Huawei AR1200-S Configuration Manual page 89

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
Procedure
l
l
Issue 02 (2012-03-30)
Setting the session thresholds for system-level traffic statistics and monitoring
1.
Run:
system-view
The system view is displayed.
2.
Run:
firewall statistics system enable
The system-level traffic statistics and monitoring are enabled.
By default, the system-level traffic statistics and monitoring is disabled.
3.
Run:
firewall statistics system connect-number { frag | icmp | tcp | tcp-proxy
| udp } high high-threshold low low-threshold
The session thresholds for the system-level traffic statistics and monitoring are set.
For the system-level traffic statistics, you can set the threshold for each type of session.
For example, you can set the upper threshold for TCP sessions to 15000 and lower
threshold to 12000. When the number of TCP sessions in all interzones exceeds 15000,
the AR1200-S denies all new TCP sessions in the interzone and reports an alarm to
the information center. If traffic volume falls to 12000 below the lower threshold, the
AR1200-S generates the recovery log and sends the log to the information center.
By default, the upper threshold and lower threshold for each type of protocol packets
are 16384 and 12288.
Setting the session thresholds for zone-level traffic statistics and monitoring
1.
Run:
system-view
The system view is displayed.
2.
Run:
firewall zone zone-name
The zone view is displayed.
3.
Run:
statistics zone enable { inzone | outzone }
The zone-level traffic statistics and monitoring are enabled.
By default, the zone-level traffic statistics and monitoring is disabled.
4.
Run:
statistics connect-number zone { inzone | outzone } { icmp | tcp | udp }
high high-threshold low low-threshold
The session thresholds for the zone-level traffic statistics and monitoring are set.
You can set the thresholds for TCP and UDP sessions in the inbound and outbound
directions. For example, you can set the threshold of inbound TCP sessions to 15000.
When the number of TCP sessions initiated by this zone exceeds 15000, the AR1200-
S denies new TCP sessions from this zone.
By default, the upper threshold and lower threshold for each type of protocol packets
are 16384 and 12288.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 Firewall Configuration
75

Advertisement

Table of Contents
loading

Table of Contents