Enabling The Login Delay; Displaying And Maintaining Attack Detection And Prevention - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enable login attack
prevention.
3.
Set the maximum number
of successive login
failures.
4.
Set the block period
during which a login
attempt is blocked.
5.
Enable the global blacklist
feature.

Enabling the login delay

The login delay feature delays the device from accepting a login request from a user after the user
fails a login attempt. This feature can slow down login dictionary attacks.
The login delay feature is independent of the login attack prevention feature.
To enable the login delay:
Step
1.
Enter system view.
2.
Enable the login delay
feature.
Displaying and maintaining attack detection and
prevention
Use the display commands in any view and the reset commands in user view.
To display and maintain attack detection and prevention:
Task
(In standalone mode.) Display attack detection
and prevention statistics on an interface.
(In IRF mode.) Display attack detection and
prevention statistics on an interface.
(In standalone mode.) Display attack detection
and prevention statistics for the device.
(In IRF mode.) Display attack detection and
prevention statistics for the device.
Display attack defense policy configuration.
Command
system-view
attack-defense login enable
attack-defense login max-attempt
max-attempt
attack-defense login
block-timeout minutes
blacklist global enable
Command
system-view
attack-defense login
reauthentication-delay seconds
Command
display attack-defense statistics interface
interface-type interface-number [ slot slot-number ]
display attack-defense statistics interface
interface-type interface-number [ chassis
chassis-number slot slot-number ]
display attack-defense statistics local [ slot
slot-number ]
display attack-defense statistics local [ chassis
chassis-number slot slot-number ]
display attack-defense policy [ policy-name ]
393
Remarks
N/A
By default, login attack prevention
is disabled.
The default value is three.
The default value is 60 minutes.
By default, the global blacklist
feature is disabled.
Remarks
N/A
By default, the login delay feature
is disabled. The device does not
delay accepting a login request
from a user who has failed a login
attempt.

Advertisement

Table of Contents
loading

Table of Contents