Verifying The Configuration - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

# Configure SYN flood attack detection for 192.168.2.1. Set the threshold for triggering SYN flood
attack prevention to 5000 and specify logging and drop as the actions for SYN packets that are
destined for the protected IP address.
[Switch-attack-defense-policy-a1] syn-flood detect ip 192.168.2.1 threshold 5000 action
logging drop
# Enable global SYN flood attack detection, set the global threshold for triggering SYN flood attack
prevention to 2000, and specify logging as the global protection action.
[Switch-attack-defense-policy-a1] syn-flood detect non-specific
[Switch-attack-defense-policy-a1] syn-flood threshold 2000
[Switch-attack-defense-policy-a1] syn-flood action logging
[Switch-attack-defense-policy-a1] quit
# Apply the attack defense policy to the device.
[Switch] attack-defense local apply policy a1

Verifying the configuration

# Verify that the attack defense policy a1 is correctly configured.
[Switch] display attack-defense policy a1
Attack-defense Policy Information
--------------------------------------------------------------------------
Policy name
Applied list
--------------------------------------------------------------------------
Exempt IPv4 ACL
Exempt IPv6 ACL
--------------------------------------------------------------------------
Actions: CV-Client verify
Signature attack defense configuration:
Signature name
Fragment
Impossible
Teardrop
Tiny fragment
IP option abnormal
Smurf
Traceroute
Ping of death
Large ICMP
Max length
Large ICMPv6
Max length
TCP invalid flags
TCP null flag
TCP all flags
TCP SYN-FIN flags
TCP FIN only flag
TCP Land
Winnuke
: a1
: Local
: Not configured
: Not configured
BS-Block source
L-Logging
Defense
Disabled
Disabled
Disabled
Disabled
Disabled
Enabled
Disabled
Disabled
Disabled
4000 bytes
Disabled
4000 bytes
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
Disabled
466
D-Drop
N-None
Level
Actions
low
L
medium
L,D
medium
L,D
low
L
medium
L,D
medium
L,D
low
L
medium
L,D
info
L
info
L
medium
L
medium
L
medium
L
medium
L
medium
L
medium
L,D
medium
L,D

Advertisement

Table of Contents
loading

Table of Contents