Optional) Configuring The Rule For Sending Packets To The Cpu - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
Context
You can create a blacklist and add users matching bound ACL rules to the blacklist. The packets
sent from the users in the blacklist are discarded by default. The S3700 supports the flexible
setting of the blacklist through ACLs.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
cpu-defend policy policy-name
The attack defense policy view is displayed.
Step 3 Run:
blacklist blacklist-id acl acl-number
A customized blacklist is created.
A maximum of 4 blacklists can be configured on the S3700
The ACL used by the blacklist can be a basic ACL, an advanced ACL, or a layer 2 ACL. For
details about the configuration procedure, see
By default, no blacklist is configured on the S3700.
----End
6.3.4 (Optional) Configuring the Rule for Sending Packets to the
CPU
The rule for sending packets to the CPU can be car or deny. You can configure only the rule
for sending packets of BGP and FTP connections to the CPU for linkup-car.
Context
Issue 01 (2011-07-15)
NOTE
The rule applied to the same packet sent to the CPU can be car or deny. If both car and deny are set, the
rule that was configured later takes effect.
After FTP, BGP and OSPF connections are set up, if the CIR and CBS of linkup-car are not set, the default
CIR and CBS are used for sending packets of FTP, BGP and OSPF connections.
You are advised to use the default CAR value on the S3700.
The priorities of application layer association, rate limit for protocol packets (limit for the number of packets
sent to the CPU and limit for the number of bytes sent to the CPU), rate limit for all the packets on an
interface, and rate limit for packets in queues are as follows:
l
The rate limit defined by application layer association has the highest priority.
l
The rate limit for protocol packets has the secondary highest priority. If the rate limit for the number
of packets sent to the CPU and the rate limit for the number of bytes sent to the CPU are set, a smaller
value takes effect.
l
The rate limit for packets in queues has the secondary lowest priority.
l
The rate limit for all the packets on an interface has the lowest priority.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
6 Local Attack Defense Configuration
10.3 Configuring an
ACL.
180

Advertisement

Table of Contents
loading

Table of Contents