Huawei S9700 Series Configuration Manual page 89

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
[SPU] display firewall blacklist all
Firewall Blacklist Items :
------------------------------------------------------------------------
IP-Address
------------------------------------------------------------------------
202.39.1.2
------------------------------------------------------------------------
total number is : 1
Run the display firewall defend command on the SPU, and the result is as follows:
[SPU] display firewall defend port-scan
defend-flag
max-rate
blacklist-expire-time
[SPU] display firewall defend ip-sweep
defend-flag
max-rate
blacklist-expire-time
----End
Configuration Files
l
Issue 01 (2012-03-15)
Reason
Manual
Configuration file of the SPU
#
sysname SPU
#
interface Eth-Trunk1
#
interface XGigabitEthernet0/0/1
eth-trunk 1
#
interface XGigabitEthernet0/0/2
eth-trunk 1
#
firewall zone trust
priority 100
#
firewall zone untrust
priority 1
#
firewall interzone trust untrust
firewall enable
#
firewall blacklist enable
firewall blacklist 202.39.1.2
firewall defend ip-sweep enable
firewall defend port-scan enable
firewall defend ip-sweep max-rate 5000
firewall defend ip-sweep blacklist-expire-time 30
firewall defend port-scan max-rate 5000
firewall defend port-scan blacklist-expire-time 30
#
interface Eth-Trunk1.1
control-vid 101 dot1q-termination
dot1q termination vid 101
ip address 201.0.0.1 255.255.255.0
arp broadcast enable
zone trust
#
interface Eth-Trunk1.2
control-vid 102 dot1q-termination
dot1q termination vid 102
ip address 202.0.0.1 255.255.255.0
arp broadcast enable
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Expire-Time(m) VPN-Instance
Permanent
: enable
: 5000
(pps)
: 30
(m)
: enable
: 5000
(pps)
: 30
(m)
2 Firewall Configuration
78

Advertisement

Table of Contents
loading

Table of Contents