Defense Udp-Flood Rate-Threshold - HP HSR6600 Command Reference Manual

Hide thumbs Also See for HSR6600:
Table of Contents

Advertisement

defense udp-flood rate-threshold

Use defense udp-flood rate-threshold to configure the global action and silence thresholds for UDP flood
attack protection. The device uses the global attack protection thresholds to protect the IP addresses for
which you do not configure attack protection parameters specifically.
Use undo defense udp-flood rate-threshold to restore the default.
Syntax
defense udp-flood rate-threshold high rate-number [ low rate-number ]
undo defense udp-flood rate-threshold
Default
The global action threshold is 1000 packets per second and the global silence threshold is 750 packets
per second.
Views
Attack protection policy view
Default command level
2: System level
Parameters
high rate-number: Sets the global action threshold for UDP flood attack protection. The rate-number
argument indicates the number of UDP packets sent to an IP address per second and is in the range of
1 to 64000. With the UDP flood attack protection enabled, the device enters attack detection state.
When the device detects that the sending rate of UDP packets destined for an IP address constantly
reaches or exceeds the specified action threshold, the device considers the IP address to be under attack,
enters attack protection state, and takes protection actions as configured.
low rate-number: Sets the global silence threshold for UDP flood attack protection. The rate-number
argument indicates the number of UDP packets sent to an IP address per second and is in the range of
1 to 64000. When the device is in attack protection state, if it detects that the sending rate of UDP
packets destined for an IP address drops below the silence threshold, it considers that the attack to the
IP address is over, returns to attack detection state, and stops the protection actions.
Usage guidelines
Adjust the thresholds according to your actual network conditions. For the protected objects that usually
have high UDP traffic, set a bigger action threshold to avoid impact on normal services. For poor network
conditions, or attack-sensitive networks, you can set a smaller action threshold. If the link bandwidth of
the protected network is small, you can set a smaller silence threshold to help release the network traffic
pressure.
Examples
# Configure UDP flood attack protection, set the global action threshold to 3000 packets per second and
the global silence threshold to 1000 packets per second.
<Sysname> system-view
[Sysname] attack-defense policy 1
[Sysname-attack-defense-policy-1] defense udp-flood rate-threshold high 3000 low 1000
Related commands
defense udp-flood action drop-packet
473

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hp 6600

Table of Contents