Configuring System Guard Against Tcn Attacks - H3C S5600 Series Operation Manual

Hide thumbs Also See for H3C S5600 Series:
Table of Contents

Advertisement

Operation Manual – 802.1x and System Guard
H3C S5600 Series Ethernet Switches
Configuring parameters related to MAC address learning
Follow these steps to configure System Guard against IP attacks:
Enter system view
Enable System Guard
against IP attacks
Set the maximum number
of infected hosts that can
be concurrently monitored
Set the maximum number
of addresses that the
system can learn, the
maximum number of
times an address can be
hit before an action is
taken and the address
isolation time (presented
in the number of multiples
of MAC address aging
time)
Note:
The correlations among the arguments of the system-guard ip detect-threshold
command can be clearly described with this example: If you set ip-record-threshold,
record-times-threshold and isolate-time to 30, 1 and 3 respectively, when the system
detects successively three times that over 50 IP packets (destined for an address other
that an IP address of the switch) from a source IP address are received within a period
of 10 seconds, the system considers that it is being attacked — the system sorts out
that source IP address and waits a period of 5 times the MAC address aging time
before learning the destination IP address(es) of packets from that source IP address
again.

4.2.2 Configuring System Guard Against TCN Attacks

Configuration of System Guard against TCN attacks includes these tasks:
Enabling System Guard against TCN attacks
Setting the threshold of TCN/TC packet receiving rate
Follow these steps to configure System Guard against TCN attacks:
Enter system view
To do...
system-view
system-guard ip enable
system-guard ip
detect-maxnum number
system-guard ip
detect-threshold
ip-record-threshold
record-times-threshold
isolate-time
To do...
system-view
Chapter 4 System Guard Configuration
Use the command...
Use the command...
4-2
Remarks
Required
Disabled by default
Optional
30 by default
Optional
By default,
ip-record-threshold is 30;
record-times-threshold is
1, and isolate-time is 3.
Remarks

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5600-26cS5600-26c-pwrS5600-26fS5600-50cS5600-50c-pwr

Table of Contents