Configuring The Blacklist; Establishing The Configuration Task - Huawei S9700 Series Configuration Manual

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
Procedure
l
l
----End

2.5 Configuring the Blacklist

You can manually add entries to the blacklist or configure a dynamic blacklist. If you choose
the dynamic blacklist, enable IP address scanning and port scanning defense on the attack defense
module of the SPU. When the SPU detects that the connection rate of an IP address or a port
exceeds the threshold, the SPU considers that a scanning attack occurs, and adds the source IP
address to the blacklist. All the packets from this source IP address are then filtered out.

2.5.1 Establishing the Configuration Task

Before configuring the blacklist, familiarize yourself with the applicable environment, complete
the pre-configuration tasks, and obtain the data required for the configuration. This will help
you complete the configuration task quickly and accurately.
Applicable Environment
The blacklist can filter out packets sent from a specified IP address to a zone. An IP address can
be added to the blacklist manually or automatically.
When the attack defense module of the firewall detects an attack through the packet behavior,
the firewall adds the source IP address of the packet to the blacklist. All the packets from this
IP address are then filtered out.
Pre-configuration Tasks
Before configuring the blacklist, complete the following tasks:
l
l
l
Data Preparation
To configure the blacklist, you need the following data.
No.
1
2
Issue 01 (2012-03-15)
Run the display firewall interzone [ zone-name1 zone-name2 ] command to view
information about packet filtering.
Run the display acl acl-number command to view the ACL configuration.
Configuring zones and adding interfaces to the zones
Configuring the interzone and enabling the firewall function in the interzone
Enabling IP address scanning attack defense or port scanning attack defense if a dynamic
blacklist is used
Data
IP address that you want to add to the blacklist (the VPN instance can be included)
(Optional) Aging time of blacklist entries
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 Firewall Configuration
39

Advertisement

Table of Contents
loading

Table of Contents