HP FlexNetwork 10500 Series Security Configuration Manual page 489

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

You can configure flood attack detection and prevention for a specific IP address. For non-specific IP
addresses, the device uses the global attack prevention settings.
Configuring a SYN flood attack defense policy
Step
1.
Enter system view.
2.
Enter attack defense policy
view.
3.
Enable global SYN flood
attack detection.
4.
Set the global trigger
threshold for SYN flood
attack prevention.
5.
Specify global actions
against SYN flood attacks.
6.
Configure IP
address-specific SYN flood
attack detection.
Configuring an ACK flood attack defense policy
Step
1.
Enter system view.
2.
Enter attack defense policy
view.
3.
Enable global ACK flood
attack detection.
4.
Set the global trigger
threshold for ACK flood
attack prevention.
5.
Specify global actions
against ACK flood attacks.
6.
Configure IP
address-specific ACK flood
attack detection.
Configuring a SYN-ACK flood attack defense policy
Step
1.
Enter system view.
2.
Enter attack defense policy
view.
3.
Enable global SYN-ACK
flood attack detection.
Command
system-view
attack-defense policy
policy-name
syn-flood detect non-specific
syn-flood threshold
threshold-value
syn-flood action { drop |
logging } *
syn-flood detect { ip
ipv4-address | ipv6
ipv6-address } [ vpn-instance
vpn-instance-name ] [ threshold
threshold-value ] [ action { drop |
logging } * ]
Command
system-view
attack-defense policy
policy-name
ack-flood detect non-specific
ack-flood threshold
threshold-value
ack-flood action { drop |
logging } *
ack-flood detect { ip
ipv4-address | ipv6
ipv6-address } [ vpn-instance
vpn-instance-name ] [ threshold
threshold-value ] [ action { drop |
logging } * ]
Command
system-view
attack-defense policy
policy-name
syn-ack-flood detect
non-specific
475
Remarks
N/A
N/A
By default, global SYN flood attack
detection is disabled.
The default setting is 1000.
By default, no global action is
specified for SYN flood attacks.
By default, IP address-specific SYN
flood attack detection is not
configured.
Remarks
N/A
N/A
By default, global ACK flood attack
detection is disabled.
The default setting is 1000.
By default, no global action is
specified for ACK flood attacks.
By default, IP address-specific ACK
flood attack detection is not
configured.
Remarks
N/A
N/A
By default, global SYN-ACK flood
attack detection is disabled.

Advertisement

Table of Contents
loading

Table of Contents