Maintaining The Attack Defense Policy; Clearing Statistics About Packets Destined For The Cpu; Clearing Statistics About Attack Sources - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
l
----End
Example
Run the display cpu-defend policy command, and you can view information about attack
defense policy .
<Quidway> display cpu-defend policy test
Related slot : <>,
Configuration :,
Car packet-type arp-request : CIR(256)
Car all-packets pps : 500 (default)
Run the display auto-defend attack-source command, and you can view the attack source.
<Quidway> display auto-defend attack-source
Attack Source User Table (MPU):
-------------------------------------------------------------------------
-------------------------------------------------------------------------
------------------------------------------------------------------------------
Attack Source Port Table (MPU)
--------------------------------------------
InterfaceName
--------------------------------------------
GigabitEthernet0/0/1
--------------------------------------------
--------------------------------------------
Attack Source IP Table (MPU):
-------------------------------------
-------------------------------------
-------------------------------------

6.5 Maintaining the Attack Defense Policy

This section describes how to clear statistics about the attack sources and the packets sent to the
CPU.

6.5.1 Clearing Statistics About Packets Destined for the CPU

Statistics about ARP packets cannot be restored being cleared.
Procedure
Step 1 Run the reset cpu-defend statistics [ packet-type packet-type ] { all | slot slot-id } command
to clear statistics about packets directing at the CPU.
----End

6.5.2 Clearing Statistics About Attack Sources

Statistics about ARP packets cannot be restored after being cleared.
Issue 01 (2011-07-15)
Run the display auto-defend attack-source [ detail ] command to view the list of attack
sources configured globally.
MacAddress
InterfaceName
0003-5556-3244
GigabitEthernet0/0/1
Vlan:Outer/Inner
IPAddress
TOTAL Packets
10.1.1.1
12652
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
CBS(48128),
Vlan:Outer/Inner
199/299
TOTAL
199/299
156464
6 Local Attack Defense Configuration
TOTAL
156464
190

Advertisement

Table of Contents
loading

Table of Contents