Configuring a single-packet attack defense policy
Apply the single-packet attack defense policy to the interface that is connected to the external
network.
Single-packet attack detection inspects incoming packets based on the packet signature. If an attack
packet is detected, the device can take the following actions:
•
Output logs (the default action).
•
Drop attack packets.
You can also configure the device to not take any actions.
To configure a single-packet attack defense policy:
Step
1.
Enter system view.
2.
Enter attack defense
policy view.
Command
system-view
attack-defense policy policy-name
477
Remarks
N/A
N/A