H3C MSR Series Command Reference Manual page 1023

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Syntax
Centralized devices in standalone mode:
display attack-defense policy policy-name { ack-flood | dns-flood | fin-flood | flood | http-flood
| icmp-flood | rst-flood | syn-ack-flood | syn-flood | udp-flood } ip [ ip-address [ vpn
vpn-instance-name ] ] [ count ]
Distributed devices in standalone mode/centralized devices in IRF mode:
display attack-defense policy policy-name { ack-flood | dns-flood | fin-flood | flood | http-flood
| icmp-flood | rst-flood | syn-ack-flood | syn-flood | udp-flood } ip [ ip-address [ vpn
vpn-instance-name ] ] [ slot slot-number ] [ count ]
Distributed devices in IRF mode:
display attack-defense policy policy-name { ack-flood | dns-flood | fin-flood | flood | http-flood
| icmp-flood | rst-flood | syn-ack-flood | syn-flood | udp-flood } ip [ ip-address [ vpn
vpn-instance-name ] ] [ chassis chassis-number slot slot-number ] [ count ]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
policy-name: Specifies an attack defense policy by its name. The policy name is a case-insensitive
string of 1 to 31 characters. Valid characters include uppercase and lowercase letters, digits,
underscores (_), and hyphens (-).
ack-flood: Specifies ACK flood attack.
dns-flood: Specifies DNS flood attack.
fin-flood: Specifies FIN flood attack.
flood: Specifies all IPv4 flood attacks.
http-flood: Specifies HTTP flood attack.
icmp-flood: Specifies ICMP flood attack.
rst-flood: Specifies RST flood attack.
syn-ack-flood: Specifies SYN-ACK flood attack.
syn-flood: Specifies SYN flood attack.
udp-flood: Specifies UDP flood attack.
ip-address: Specifies a protected IPv4 address. If you do not specify an IPv4 address, this command
displays information about all protected IPv4 addresses.
vpn-instance vpn-instance-name: Specifies the MPLS L3VPN instance to which the IPv4 address
belongs. The vpn-instance-name argument is a case-sensitive string of 1 to 31 characters. Do not
specify this option if the IPv4 address is on the public network.
slot slot-number: Specifies a card by its slot number. If you do not specify a card, this command
displays information about IPv4 addresses protected by flood attack detection and prevention for all
cards. (Distributed devices in standalone mode.)
slot slot-number: Specifies an IRF member device by its member ID. If you do not specify a member
device, this command displays information about IPv4 addresses protected by flood attack detection
and prevention for all IRF member devices. (Centralized devices in IRF mode.)
1000

Advertisement

Table of Contents
loading

Table of Contents