Displaying And Maintaining Attack Detection And Prevention - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enable the login delay
feature.
Displaying and maintaining attack detection and
prevention
Use the display commands in any view and the reset commands in user view.
To display and maintain attack detection and prevention:
Task
Display attack detection and prevention statistics
for the device.
Display attack defense policy configuration.
Display information about IPv4 scanning
attackers.
Display information about IPv6 scanning
attackers.
Display information about IPv4 scanning attack
victims.
Display information about IPv6 scanning attack
victims.
Display flood attack detection and prevention
statistics for an IPv4 address.
Display flood attack detection and prevention
statistics for an IPv6 address.
Display information about IPv4 addresses
protected by flood attack detection and
prevention.
Display information about IPv6 addresses
protected by flood attack detection and
prevention.
Clear attack detection and prevention statistics
for the device.
Command
system-view
attack-defense login
reauthentication-delay seconds
Command
display attack-defense statistics local [ slot
slot-number ]
display attack-defense policy [ policy-name ]
display attack-defense scan attacker ip [ count ]
display attack-defense scan attacker ipv6 [ count ]
display attack-defense scan victim ip [ count ]
display attack-defense scan victim ipv6 [ count ]
display attack-defense { ack-flood | dns-flood |
fin-flood | flood | http-flood | icmp-flood | rst-flood |
syn-ack-flood | syn-flood | udp-flood } statistics ip
[ ip-address [ vpn vpn-instance-name ] ] [ local [ slot
slot-number ] ] [ count ]
display attack-defense { ack-flood | dns-flood |
fin-flood | flood | http-flood | icmpv6-flood | rst-flood |
syn-ack-flood | syn-flood | udp-flood } statistics ipv6
[ ipv6-address [ vpn vpn-instance-name ] ] [ local [ slot
slot-number ] ] [ count ]
display attack-defense policy policy-name { ack-flood
| dns-flood | fin-flood | flood | http-flood | icmp-flood |
rst-flood | syn-ack-flood | syn-flood | udp-flood } ip
[ ip-address [ vpn vpn-instance-name ] ] [ slot
slot-number ] [ count ]
display attack-defense policy policy-name { ack-flood
| dns-flood | fin-flood | flood | http-flood |
icmpv6-flood | rst-flood | syn-ack-flood | syn-flood |
udp-flood } ipv6 [ ipv6-address [ vpn
vpn-instance-name ] ] [ slot slot-number ] [ count ]
reset attack-defense statistics local
464
Remarks
N/A
By default, the login delay feature
is disabled. The device does not
delay accepting a login request
from a user who has failed a login
attempt.

Advertisement

Table of Contents
loading

Table of Contents