Configuring Tcp Proxy; Configuring The Blacklist Function - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

To apply an attack protection policy to an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Apply an attack protection
policy to the interface.

Configuring TCP proxy

TCP proxy is used on a device's interfaces connected to external networks to protect internal servers from
SYN flood attacks. It takes effect only on incoming packets of a TCP proxy-enabled interface.When
detecting a SYN flood attack, the device can take protection actions as configured by using the defense
syn-flood action command. If the trigger-tcp-proxy keyword is specified for the defense syn-flood action
command, the device adds a protected IP address entry for the server, and starts TCP proxy in the
specified mode to inspect and process subsequent TCP connection requests destined to the server.
To configure the TCP proxy function:
Step
1.
Enter system view.
2.
Set the TCP proxy operating
mode.
3.
Enter interface view.
4.
Enable the TCP proxy
function on the interface.

Configuring the blacklist function

You can configure a device to filter packets from certain IP addresses by configuring the blacklist
function.
The blacklist configuration includes enabling the blacklist function and adding blacklist entries. When
adding a blacklist entry, you can also configure the entry aging time. If you do not configure the aging
time, the entry never ages out, and always exist until you delete it manually.
To configure the blacklist function:
Command
system-view
interface interface-type
interface-number
attack-defense apply policy
policy-number
Command
system-view
Unidirectional mode:
tcp-proxy mode unidirection
Bidirectional mode:
undo tcp-proxy mode
interface interface-type
interface-number
tcp-proxy enable
488
Remarks
N/A
N/A
By default, no attack protection
policy is applied to any interface.
The attack protection policy to be
applied to an interface must already
exist.
Remarks
N/A
Optional.
By default, TCP proxy works in
bidirectional mode when enabled.
N/A
By default, TCP proxy is disabled on
an interface.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents