Configuring Login Attack Prevention; Enabling The Login Delay - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enable the global blacklist
feature.
3.
Add a user blacklist entry.
4.
(Optional.) Enable logging
for the blacklist feature.

Configuring login attack prevention

The login attack prevention feature detects a login DoS attack if a user fails the maximum number of
successive login attempts. The feature triggers the blacklist feature to add the user's IP to the
blacklist. Following login attempts from the user is blocked for the block period. For login attack
prevention to take effect, you must enable the global blacklist feature.
This feature can effectively prevent login DoS attacks.
To configure login attack prevention:
Step
1.
Enter system view.
2.
Enable login attack
prevention.
3.
Set the maximum number
of successive login
failures.
4.
Set the block period
during which a login
attempt is blocked.
5.
Enable the global blacklist
feature.

Enabling the login delay

The login delay feature delays the device from accepting a login request from a user after the user
fails a login attempt. This feature can slow down login dictionary attacks.
The login delay feature is independent of the login attack prevention feature.
To enable the login delay:
Step
1.
Enter system view.
2.
Enable the login delay
feature.
Command
system-view
blacklist global enable
blacklist user user-name [ timeout
minutes ]
blacklist logging enable
Command
system-view
attack-defense login enable
attack-defense login max-attempt
max-attempt
attack-defense login
block-timeout minutes
blacklist global enable
Command
system-view
attack-defense login
reauthentication-delay seconds
487
Remarks
N/A
By default, the global blacklist
feature is disabled.
By default, no user blacklist
entries exist.
By default, logging is disabled for
the blacklist feature.
Remarks
N/A
By default, login attack prevention
is disabled.
The default value is three.
The default value is 60 minutes.
By default, the global blacklist
feature is disabled.
Remarks
N/A
By default, the login delay feature
is disabled. The device does not
delay accepting a login request
from a user who has failed a login
attempt.

Advertisement

Table of Contents
loading

Table of Contents