HPE FlexNetwork 7500 Series Security Configuration Manual page 412

Table of Contents

Advertisement

ICMP timestamp reply
ICMP information request
ICMP information reply
ICMP address mask request
ICMP address mask reply
ICMPv6 echo request
ICMPv6 echo reply
ICMPv6 group membership query
ICMPv6 group membership report
ICMPv6 group membership reduction
ICMPv6 destination unreachable
ICMPv6 time exceeded
ICMPv6 parameter problem
ICMPv6 packet too big
Scan attack defense configuration:
Defense : Enabled
Level
: low
Actions : L,BS(10)
Flood attack defense configuration:
Flood type
Global thres(pps)
SYN flood
1000(default)
ACK flood
1000(default)
SYN-ACK flood
1000(default)
RST flood
1000(default)
FIN flood
1000(default)
UDP flood
1000(default)
ICMP flood
1000(default)
ICMPv6 flood
1000(default)
DNS flood
1000(default)
HTTP flood
1000(default)
Flood attack defense for protected IP addresses:
Address
10.1.1.2
# Verify that the attack detection and prevention takes effect on GigabitEthernet 1/0/2.
[Device] display attack-defense statistics interface gigabitethernet 1/0/2
Attack policy name: a1
Scan attack defense statistics:
AttackType
Port scan
IP sweep
Distribute port scan
Flood attack defense statistics:
AttackType
SYN flood
Signature attack defense statistics:
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Global actions
-
-
-
-
-
-
-
-
-
-
VPN instance Flood type
--
SYN-FLOOD
AttackTimes Dropped
2
3
1
AttackTimes Dropped
1
398
info
L
info
L
info
L
info
L
info
L
info
L
info
L
info
L
info
L
info
L
info
L
info
L
info
L
info
L
Service ports
-
Disabled
-
Disabled
-
Disabled
-
Disabled
-
Disabled
-
Disabled
-
Disabled
-
Disabled
53
Disabled
80
Disabled
Thres(pps) Actions Ports
5000
L,D
0
0
0
5000
Non-specific
-

Advertisement

Table of Contents
loading

Table of Contents