Configuring Login Attack Prevention; Enabling The Login Delay - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
3.
(Optional.) Add an IPv4
blacklist entry.
4.
(Optional.) Add an IPv6
blacklist entry.
5.
(Optional.) Enable logging
for the blacklist feature.
6.
Enter interface view.
7.
Enable the blacklist
feature on the interface.

Configuring login attack prevention

The login attack prevention feature detects a login DoS attack if a user fails the maximum number of
successive login attempts. The feature triggers the blacklist feature to add the user's IP to the
blacklist. Following login attempts from the user is blocked for the block period. For login attack
prevention to take effect, you must enable the global blacklist feature.
This feature can effectively prevent login DoS attacks.
To configure login attack prevention:
Step
1.
Enter system view.
2.
Enable login attack
prevention.
3.
Set the maximum number
of successive login
failures.
4.
Set the block period
during which a login
attempt is blocked.
5.
Enable the global blacklist
feature.

Enabling the login delay

The login delay feature delays the device from accepting a login request from a user after the user
fails a login attempt. This feature can slow down login dictionary attacks.
The login delay feature is independent of the login attack prevention feature.
To enable the login delay:
Step
1.
Enter system view.
Command
blacklist ip source-ip-address
[ vpn-instance vpn-instance-name ]
[ timeout minutes ]
blacklist ipv6 source-ipv6-address
[ vpn-instance vpn-instance-name ]
[ timeout minutes ]
blacklist logging enable
interface interface-type
interface-number
blacklist enable
Command
system-view
attack-defense login enable
attack-defense login max-attempt
max-attempt
attack-defense login
block-timeout minutes
blacklist global enable
Command
system-view
482
Remarks
By default, no IPv4 blacklist
entries exist.
By default, no IPv6 blacklist
entries exist.
By default, logging is disabled for
the blacklist feature.
N/A
By default, the blacklist feature is
disabled on the interface.
Remarks
N/A
By default, login attack prevention
is disabled.
The default value is three.
The default value is 60 minutes.
By default, the global blacklist
feature is disabled.
Remarks
N/A

Advertisement

Table of Contents
loading

Table of Contents