Download Print this page

HP FlexNetwork MSR Series Command Reference Manual page 854

Comware 7 security
Hide thumbs Also See for FlexNetwork MSR Series:

Advertisement

network-operator
Parameters
policy-name: Specifies an attack defense policy by its name. The policy name is a case-insensitive
string of 1 to 31 characters. Valid characters include uppercase and lowercase letters, digits,
underscores (_), and hyphens (-).
ack-flood: Specifies ACK flood attack.
dns-flood: Specifies DNS flood attack.
fin-flood: Specifies FIN flood attack.
flood: Specifies all IPv4 flood attacks.
http-flood: Specifies HTTP flood attack.
icmp-flood: Specifies ICMP flood attack.
rst-flood: Specifies RST flood attack.
syn-ack-flood: Specifies SYN-ACK flood attack.
syn-flood: Specifies SYN flood attack.
udp-flood: Specifies UDP flood attack.
ip-address: Specifies a protected IPv4 address. If you do not specify an IPv4 address, this command
displays information about all protected IPv4 addresses.
vpn-instance vpn-instance-name: Specifies the MPLS L3VPN instance to which the IPv4 address
belongs. The vpn-instance-name argument is a case-sensitive string of 1 to 31 characters. Do not
specify this option if the IPv4 address is on the public network.
slot slot-number: Specifies a card by its slot number. If you do not specify a card, this command
displays information about IPv4 addresses protected by flood attack detection and prevention for all
cards. (Distributed devices in standalone mode.)
slot slot-number: Specifies an IRF member device by its member ID. If you do not specify a member
device, this command displays information about IPv4 addresses protected by flood attack detection
and prevention for all IRF member devices. (Centralized devices in IRF mode.)
chassis chassis-number slot slot-number: Specifies a card on an IRF member device. The
chassis-number argument represents the member ID of the IRF member device. The slot-number
argument represents the slot number of the card. If you do not specify a card, this command displays
information about IPv4 addresses protected by flood attack detection and prevention for all cards.
(Distributed devices in IRF mode.)
count: Displays the number of matching IPv4 addresses protected by flood attack detection and
prevention.
Examples
# (Centralized devices in standalone mode.) Display information about all IPv4 addresses protected
by flood attack detection and prevention in the attack defense policy abc.
<Sysname> display attack-defense policy abc flood ip
IP address
123.123.123.123 a012345678901234 SYN-ACK-FLOOD 100
201.55.7.45
192.168.11.5
# (Distributed devices in standalone mode/centralized devices in IRF mode.) Display information
about all IPv4 addresses protected by flood attack detection and prevention in the attack defense
policy abc.
<Sysname> display attack-defense policy abc flood ip
Slot 1:
VPN instance
Type
--
ICMP-FLOOD
--
DNS-FLOOD
Rate threshold(PPS) Dropped
100
23
836
4294967295
10
100

Advertisement

loading