Applying The Attack Defense Policy; Checking The Configuration - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
cpu-defend policy policy-name
The attack defense policy view is displayed.
Step 3 Run:
queue packet-type packet-type queue-value
The queue number for protocol packets sent to the CPU is set.
By default, the queue number for protocol packets sent to the CPU can be displayed by display
cpu-defend configuration all command.
----End

6.3.6 Applying the Attack Defense Policy

After an attack defense policy is created, you must apply the attack defense policy in the system
view. Otherwise, the attack defense policy does not take effect.
Context
When the S3700 is stacked, the attack defense policy is applied to all switches in a stack.
Procedure
l
----End

6.3.7 Checking the Configuration

This section describes how to check the configuration of the attack defense policy.
Procedure
l
l
Issue 01 (2011-07-15)
Applying the attack defense policy in the system view
1.
Run:
system-view
The system view is displayed.
2.
Run:
cpu-defend-policy policy-name global
An attack defense policy is applied.
Run the display cpu-defend policy policy-name command to view information about the
attack defense policy.
Run the display cpu-defend statistics [ packet-type packet-type ] { all | slot slot-id }
command to view the statistics on packets sent to the CPU.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
6 Local Attack Defense Configuration
182

Advertisement

Table of Contents
loading

Table of Contents