HP 6600 Security Configuration Manual page 499

Table of Contents

Advertisement

Step
4.
Configure the ICMP packet
length threshold that triggers
large ICMP attack protection.
5.
Configure the device to drop
single-packet attack packets.
6.
Return to system view.
7.
Enable attack protection logging.
Configuring a scanning attack protection policy
The scanning attack protection function detects scanning attacks by monitoring the establishment rate of
connections to the target systems. It is usually applied to interfaces connecting external networks and
inspects only the inbound packets of the interfaces. If the device detects that the rate at which an IP
address initiates connections reaches or exceeds the pre-defined threshold, depending on your
configuration, the device adds the IP address to the blacklist to drop subsequent packets received from
the IP address.
To configure a policy for preventing scanning attacks:
Step
1.
Enter system view.
2.
Enter attack protection
policy view.
3.
Enable scanning attack
protection.
4.
Specify the connection
rate threshold that
triggers scanning attack
protection.
Configure the blacklist
5.
function for scanning
attack protection.
6.
Return to system view.
Command
signature-detect large-icmp
max-length length
signature-detect action
drop-packet
quit
attack-defense logging enable
Command
system-view
attack-defense policy policy-number
defense scan enable
defense scan max-rate rate-number
Enable the blacklist function for
scanning attack protection
defense scan add-to-blacklist
Set the aging time for entries blacklisted
by the scanning attack protection
function
defense scan blacklist-timeout minutes
quit
485
Remarks
Optional.
4000 bytes by default.
Optional.
By default, the device does not
process the attack packets if it
detects an attack.
N/A
Optional.
By default, attack protection
logging is disabled.
Remarks
N/A
N/A
Disabled by default.
Optional.
4000 connections per second
by default.
Optional.
By default:
Blacklist function for
scanning attack protection is
disabled.
The aging time for entries
blacklisted by the scanning
attack protection function is
10 minutes.
N/A

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents