Download Print this page

Display Attack-Defense Policy Ipv6 - HP FlexNetwork MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for FlexNetwork MSR Series:

Advertisement

Field
VPN instance
Type
Rate threshold(PPS)
Dropped

display attack-defense policy ipv6

Use display attack-defense policy ipv6 to display information about IPv6 addresses protected by
flood attack detection and prevention.
Syntax
Centralized devices in standalone mode:
display attack-defense policy policy-name { ack-flood | dns-flood | fin-flood | flood | http-flood
| icmpv6-flood | rst-flood | syn-ack-flood | syn-flood | udp-flood } ipv6 [ ipv6-address [ vpn
vpn-instance-name ] ] [ count ]
Distributed devices in standalone mode/centralized devices in IRF mode:
display attack-defense policy policy-name { ack-flood | dns-flood | fin-flood | flood | http-flood
| icmpv6-flood | rst-flood | syn-ack-flood | syn-flood | udp-flood } ipv6 [ ipv6-address [ vpn
vpn-instance-name ] ] [ slot slot-number ] [ count ]
Distributed devices in IRF mode:
display attack-defense policy policy-name { ack-flood | dns-flood | fin-flood | flood | http-flood
| icmpv6-flood | rst-flood | syn-ack-flood | syn-flood | udp-flood } ipv6 [ ipv6-address [ vpn
vpn-instance-name ] ] [ chassis chassis-number slot slot-number ] [ count ]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
policy-name: Specifies an attack defense policy by its name. The policy name is a case-insensitive
string of 1 to 31 characters. Valid characters include uppercase and lowercase letters, digits,
underscores (_), and hyphens (-).
ack-flood: Specifies ACK flood attack.
dns-flood: Specifies DNS flood attack.
fin-flood: Specifies FIN flood attack.
flood: Specifies all IPv6 flood attacks.
http-flood: Specifies HTTP flood attack.
icmpv6-flood: Specifies ICMPv6 flood attack.
rst-flood: Specifies RST flood attack.
Description
MPLS L3VPN instance to which the protected IPv4 address belongs. If
the protected IPv4 address is on the public network, this field displays
hyphens (--).
Type of the flood attack.
Threshold for triggering the flood attack prevention, in units of packets
sent to the IP address per second. If no rate threshold is set, this field
displays the default value 1000.
Number of dropped attack packets. If the prevention action is logging, this
field displays 0.
838

Advertisement

loading