Setting The Parameters For Flood Attack Defense - Huawei S9700 Series Configuration Manual

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
The Ping of Death attack defense is enabled.
Step 12 Run:
firewall defend port-scan enable
The port scanning attack defense is enabled.
After the parameters for port scanning attack defense are set, you must enable the port scanning
attack defense function; otherwise, the SPU does not detect the attack packets or take attack
defense measures.
Step 13 Run:
firewall defend smurf enable
The Smurf attack defense is enabled.
Step 14 Run:
firewall defend syn-flood enable
The SYN Flood attack defense is enabled.
After the parameters for SYN Flood attack defense are set, you must enable the SYN Flood
attack defense function; otherwise, the SPU does not detect the attack packets or take attack
defense measures.
Step 15 Run:
firewall defend tcp-flag enable
The TCP flag attack defense is enabled.
Step 16 Run:
firewall defend teardrop enable
The Teardrop attack defense is enabled.
Step 17 Run:
firewall defend tracert enable
The Tracert attack defense is enabled.
Step 18 Run:
firewall defend udp-flood enable
The UDP Flood attack defense is enabled.
After the parameters for UDP Flood attack defense are set, you must enable the UDP Flood
attack defense function; otherwise, the SPU does not detect the attack packets or take attack
defense measures.
Step 19 Run:
firewall defend winnuke enable
The WinNuke attack defense is enabled.
By default, no attack defense function is enabled.
----End

2.11.3 Setting the Parameters for Flood Attack Defense

Issue 01 (2012-03-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 Firewall Configuration
56

Advertisement

Table of Contents
loading

Table of Contents