Configuring Large Icmp Packet Attack Defense - Huawei S9700 Series Configuration Manual

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
Context
Steps 2-4 are optional and can be performed in any sequence. You can select these steps to defend
different types of Flood attacks.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
firewall defend icmp-flood { ip ip-address [ vpn-instance vpn-instance-name ] |
zone zone-name } [ max-rate rate-value ]
The parameters for ICMP Flood attack defense are set.
Step 3 Run:
firewall defend syn-flood { ip ip-address
zone zone-name } [ flow-rate rate-value | max-rate rate-value | tcp-proxy { auto |
off | on } ]*
The parameters for SYN Flood attack defense are set.
Step 4 Run:
firewall defend udp-flood { ip ip-address
zone zone-name } [ flow-rate rate-value | max-rate rate-value ]
The parameters for UDP Flood attack defense are set.
To prevent Flood attacks, you need to specify the zones or IP addresses to be protected;
otherwise, the attack defense parameters are invalid. You can also specify the maximum session
rate. When the session rate exceeds the limit, the SPU considers that an attack occurs and takes
measures.
For Flood attack defense, the priority of IP addresses is higher than the priority of zones. If Flood
attack defense is enabled for both a specified IP address and the zone where the IP address
resides, then the attack defense for the IP address takes effect. If you cancel the attack defense
for the IP address, the attack defense for the zone takes effect.
By default, the maximum session rate for Flood attacks is 1000 pps, and the TCP proxy is enabled
for the SYN Flood attack defense.
For Flood attack defense, you can specify up to 4096 IP addresses to protect.
----End

2.11.4 Configuring Large ICMP Packet Attack Defense

Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
Issue 01 (2012-03-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 Firewall Configuration
[ flow-rate rate-value ]
[ vpn-instance vpn-instance-name ] |
[ vpn-instance vpn-instance-name ] |
57

Advertisement

Table of Contents
loading

Table of Contents