H3C MSR Series Command Reference Manual page 1020

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

ICMP address mask reply
ICMPv6 echo request
ICMPv6 echo reply
ICMPv6 group membership query
ICMPv6 group membership report
ICMPv6 group membership reduction
ICMPv6 destination unreachable
ICMPv6 time exceeded
ICMPv6 parameter problem
ICMPv6 packet too big
Scan attack defense configuration:
Defense: Disabled
Level: Medium
Actions: L
Flood attack defense configuration:
Flood type
Global thres(pps)
SYN flood
1000
ACK flood
1000
SYN-ACK flood
1000
RST flood
200
FIN flood
1000
UDP flood
1000
ICMP flood
1000
ICMPv6 flood
1000
DNS flood
10000
HTTP flood
10000
Flood attack defense for protected IP addresses:
Address
1::1
192.168.1.1
1::1
2013:2013:2013:2013:
2013:2013:2013:2013
Table 154 Command output
Field
Policy name
Applied list
Exempt IPv4 ACL
Exempt IPv6 ACL
Disabled
Enabled
Disabled
Disabled
Disabled
Disabled
Enabled
Enabled
Disabled
Disabled
Global actions
-
-
-
-
L,D
-
-
CV
-
-
VPN instance Flood type
--
FIN-FLOOD
A01234567890 SYN-ACK-FLOOD 10
123456789012
3456789
--
FIN-FLOOD
A0123456789
DNS-FLOOD
Description
Name of the attack defense policy.
List of interfaces to which the attack defense policy is applied. If the policy
is applied to the device, this field displays Local.
IPv4 ACL used for attack detection exemption.
IPv6 ACL used for attack detection exemption.
997
Medium
L,D
Medium
L,D
Medium
L,D
Medium
L,D
Medium
L,D
Medium
L,D
Medium
L,D
Medium
L,D
Medium
L,D
Medium
L,D
Service ports
Non-specific
-
Disabled
-
Enabled
-
Disabled
-
Enabled
-
Disabled
-
Disabled
-
Disabled
-
Disabled
30,61 to 62
Enabled
80,8080
Enabled
Thres(pps)
Actions Ports
10
L,D
-
-
L
100
L,CV
-
-
-
53

Advertisement

Table of Contents
loading

Table of Contents