Specifying A Mac Binding Server On An Interface; Configuring Portal Http Attack Defense - H3C SR8800-F Configuration Manual

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

Step
8.
(Optional.) Specify the type
of the MAC binding server
9.
(Optional.) Specify the
version of the portal protocol.
10. (Optional.) Specify the
timeout the device waits for
portal authentication to
complete after receiving the
MAC binding query
response.
11. (Optional.) Set the aging time
for MAC-trigger entries.

Specifying a MAC binding server on an interface

After a MAC binding server is specified on an interface, the device can implement MAC-based quick
portal authentication for portal users on the interface.
To specify a MAC binding server on an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Specify a MAC binding
server on the interface.

Configuring portal HTTP attack defense

About portal HTTP attack defense
Use this feature to avoid high resource usage caused by excessive HTTP requests from
unauthenticated portal users.
This feature counts the number of HTTP requests to be redirected on a per destination IP address
basis. If the number of HTTP requests for a destination IP address reaches the blocking threshold
within a statistical interval, the device starts a blocking timer for the IP address. Before the blocking
timer expires, the device discards all HTTP requests destined for the IP address.
You can set the maximum number of destination IP addresses for which the device can perform
portal HTTP attack defense.
Procedure
To configure portal HTTP attack defense:
Step
1.
Enter system view.
2.
Enable portal HTTP attack
defense.
Command
server-type { cmcc | imc }
version version-number
authentication-timeout minutes
aging-time seconds
Command
system-view
interface interface-type
interface-number
portal apply mac-trigger-server
server-name
Command
system-view
portal http-defense enable
326
Remarks
By default, the type of a MAC
binding server is IMC.
By default, the version of the
portal protocol is 1.
By default, the portal
authentication timeout time is 3
minutes.
By default, the aging time for
MAC-trigger entries is 300
seconds.
Remarks
N/A
The interface must be a Layer 3
interface.
By default, no MAC binding server
is specified on an interface.
Remarks
N/A
By default, portal HTTP attack
defense is disabled.

Advertisement

Table of Contents
loading

Table of Contents