Applying An Attack Defense Policy To An Interface; Applying An Attack Defense Policy To The Device - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

Step

Applying an attack defense policy to an interface

An attack defense policy does not take effect unless you apply it to an interface.
If you apply an attack defense policy to a global interface, specify a traffic processing slot for the
interface. If you do not specify a traffic processing slot, the policy cannot correctly detect and prevent
scanning and flood attacks.
To apply an attack defense policy to an interface:
Step
1.
Enter system view.
2.
Enter system view.
3.
Apply an attack defense
policy to the interface.
4.
(Optional.) Specify a traffic
processing slot for the
interface.

Applying an attack defense policy to the device

An attack defense policy applied to the device itself rather than the interfaces detects packets
destined for the device and prevents attacks targeted at the device.
The device uses hardware to implement packet forwarding and uses software to process packets if
the packets are destined for the device. The software does not provide any attack defense features,
so you must apply an attack defense policy to the device to prevent attacks aimed at the device.
If a device and its interfaces have attack defense policies applied, a packet destined for the device is
processed as follows:
1.
The policy applied to the receiving interface processes the packet.
2.
If the packet is not dropped by the receiving interface, the policy applied to the device
processes the packet.
To apply an attack defense policy to the device:
Step
1.
Enter system view.
2.
Apply an attack defense
policy to the device.
Command
| name acl-name }
Command
system-view
interface interface-type
interface-number
attack-defense apply policy
policy-name
In standalone mode:
service slot slot-number
In IRF mode:
service chassis chassis-number
slot slot-number
Command
system-view
attack-defense local apply
policy policy-name
390
Remarks
exemption is not configured.
Remarks
N/A
N/A
By default, no attack defense policy
is applied to the interface.
By default, no traffic processing slot
is specified for an interface. Traffic
on an interface is processed on the
slot at which the traffic arrives.
Remarks
N/A
By default, no attack defense policy
is applied to the device.

Advertisement

Table of Contents
loading

Table of Contents