Introduction To Ip Source Trail; Ip Source Trail Features Supported By The S9300 - Huawei Quidway S9300 Configuration Manual

Terabit routing switch v100r001c03
Table of Contents

Advertisement

6 IP Source Trail Configuration

6.1 Introduction to IP Source Trail

This section describes the principle of IP source trail.
IP source trail is a policy of preventing Denial of Service (DoS) attacks. It is mainly used to
trace the attack source and take defense measures after confirming the attack source. IP source
trail takes the statistics on traffic based on the destination IP address, source IP address, and
incoming interface of packets and determines the attack source according to the statistics.
The process of IP source trail is as follows:
1.
2.
3.

6.2 IP Source Trail Features Supported by the S9300

This section describes the IP source trail features supported by the S9300.
IP Source Trail Based on the Destination IP Address
IP source trail is configured according to the IP address of the attacked user. The CPU of an
LPU collects the packets whose destination address is the IP address of the attacked user. The
statistics are sent to the CPU of the main control board periodically or queried by the main control
board.
Global Query of the IP Source Trail Statistics
The results of global query can be displayed in brief or detailed mode:
l
l
Query of the Statistics on IP Source Trail Based on the LPU
When you query the IP source trail statistics collected by a specified LPU, the main control
board searched for the cached statistics based on the destination IP address. Then, the main
control board displays only the statistics reported by the specified LPU in brief mode.
6-2
After confirming that a user is attacked, you can configure IP source trail according to the
IP address of the user.
The CPU of a Line Processing Unit (LPU) collects the packets whose destination address
is the IP address of the attacked user. The statistics are sent to the CPU of the main control
board periodically or queried by the main control board.
The main control board determines the attack source according to the statistics. Then, you
can create an ACL on the interface that is directly connected to the possible attack source
and set the ACL in deny mode.
In brief mode, the displayed query result includes the source IP address, source interface,
total amount of traffic (number of bytes and packets), and average rate (bbp and pps) of
traffic in the statistics period.
In detailed mode, information about the current rate and maximal rate of the traffic and the
start time and end time of the traffic (the end time is replaced with the query time if the
traffic has not ended) is displayed, in addition to the preceding information displayed in
brief mode.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 01 (2009-07-28)

Advertisement

Table of Contents
loading

Table of Contents