Configuring The User Blacklist Feature; Configuring Login Attack Prevention - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

To configure the IP blacklist feature:
Step
1.
Enter system view.
2.
(Optional.) Enable the
global blacklist feature.
3.
(Optional.) Add an IPv4
blacklist entry.
4.
(Optional.) Add an IPv6
blacklist entry.
5.
(Optional.) Enable logging
for the blacklist feature.

Configuring the user blacklist feature

The user blacklist feature filters packets sourced from users in blacklist entries.
A user blacklist entry can only be manually added by using the blacklist user command. A user
blacklist entry does not age out by default. You can set an aging time for the entry.
The user blacklist feature must be used together with the user identification feature. For more
information about user identification, see "Configuring user identification."
To configure the user blacklist feature:
Step
1.
Enter system view.
2.
Enable the global blacklist
feature.
3.
Add a user blacklist entry.
4.
(Optional.) Enable logging
for the blacklist feature.

Configuring login attack prevention

The login attack prevention feature detects a login DoS attack if a user fails the maximum number of
successive login attempts. The feature triggers the blacklist feature to add the user's IP to the
blacklist. Following login attempts from the user is blocked for the block period. For login attack
prevention to take effect, you must enable the global blacklist feature.
This feature can effectively prevent login DoS attacks.
To configure login attack prevention:
Command
system-view
blacklist global enable
blacklist ip source-ip-address
[ vpn-instance vpn-instance-name ]
[ timeout minutes ]
blacklist ipv6 source-ipv6-address
[ vpn-instance vpn-instance-name ]
[ timeout minutes ]
blacklist logging enable
Command
system-view
blacklist global enable
blacklist user user-name [ timeout
minutes ]
blacklist logging enable
392
Remarks
N/A
By default, the global blacklist
feature is disabled.
If the global blacklist feature is
enabled, the blacklist feature is
enabled on all interfaces.
By default, no IPv4 blacklist
entries exist.
By default, no IPv6 blacklist
entries exist.
By default, logging is disabled for
the blacklist feature.
Remarks
N/A
By default, the global blacklist
feature is disabled.
By default, no user blacklist
entries exist.
By default, logging is disabled for
the blacklist feature.

Advertisement

Table of Contents
loading

Table of Contents