Huawei Quidway S8500 Series Command Manual page 1208

Routing switches
Hide thumbs Also See for Quidway S8500 Series:
Table of Contents

Advertisement

Command Manual – NAT&URPF&VPLS
Quidway S8500 Series Routing Switches
undo nat blacklist start
nat blacklist mode { all | amount | rate }
undo nat blacklist mode { all | amount | rate }
nat blacklist limit amount [ source user-ip ] amount-value
undo nat blacklist limit amount [ source user-ip ]
nat blacklist limit rate [ source ip ] { max max-rate | min min-rate } *
nat blacklist limit rate { source { ip limit-rate | ip-address } | limit-rate }
undo nat blacklist limit rate [ source { ip | ip-address } ]
View
System view
Parameter
start: Enable the NAT blacklist feature for the complete system.
mode { all | amount | rate }: Sets control modes. all indicates controlling both the
number of connections and the setup rate; amount indicates controlling the number of
connections; rate indicates controlling the setup rate.
Note that connections here refer to the address mapping relationships setup during
NAT; setup rates refer to the rate for setting up the relationships, that is, the number of
times for setting up the connections every second.
amount: Sets the upper threshold for total connections that can be set up.
rate: Sets the upper threshold rates at which connections are set up.
source: You can set different thresholds controlling the number of connections for
source IP addresses in the previous range. All the thresholds controlling the setup rate
for source IP addresses must be the same. Source specifies whether the thresholds
are configured for all the addresses or an individual address in the address pool.
source ip indicates the configuration of the maximum and minimum setup rates for an
individual IP address.
amount-value: Sets the maximum threshold of the total number of NAT connections
that the same user can establish.
ip: Source IP addresses.
limit-rate: Maximum or minimum setup rate.
ip-address: IP address.
user-ip: IP address. After this parameter is configured, switches set a control domain
value for each specified IP address.
Description
Use the nat blacklist command to set the NAT blacklist attributes.
Huawei Technologies Proprietary
1-8
Chapter 1 NAT Configuration Commands

Advertisement

Table of Contents
loading

Table of Contents