HP FlexNetwork 10500 Series Security Configuration Manual page 500

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

# Create the attack defense policy a1.
[Device] attack-defense policy a1
# Configure signature detection for smurf attacks, and specify logging as the prevention action.
[Device-attack-defense-policy-a1] signature detect smurf action logging
# Configure low-level scanning attack detection, specify logging and block-source as the
prevention actions, and set the blacklist entry aging time to 10 minutes.
[Device-attack-defense-policy-a1] scan detect level low action logging block-source
timeout 10
# Configure SYN flood attack detection for 10.1.1.2, set the attack prevention triggering threshold to
5000, and specify logging and drop as the prevention actions.
[Device-attack-defense-policy-a1] syn-flood detect ip 10.1.1.2 threshold 5000 action
logging drop
[Device-attack-defense-policy-a1] quit
# Apply the attack defense policy a1 to interface GigabitEthernet 1/0/2.
[Device] interface gigabitethernet 1/0/2
[Device-GigabitEthernet1/0/2] attack-defense apply policy a1
[Device-GigabitEthernet1/0/2] quit
Verifying the configuration
# Verify that the attack defense policy a1 is successfully configured.
[Device] display attack-defense policy a1
Attack-defense Policy Information
--------------------------------------------------------------------------
Policy name
Applied list
--------------------------------------------------------------------------
Exempt IPv4 ACL
Exempt IPv6 ACL
--------------------------------------------------------------------------
Actions: CV-Client verify
Signature attack defense configuration:
Signature name
Fragment
Impossible
Teardrop
Tiny fragment
IP option abnormal
Smurf
Traceroute
Ping of death
Large ICMP
Max length
Large ICMPv6
Max length
TCP invalid flags
TCP null flag
TCP all flags
TCP SYN-FIN flags
: a1
: GE1/0/2
: Not configured
: Not configured
BS-Block source
L-Logging
Defense
Disabled
Disabled
Disabled
Disabled
Disabled
Enabled
Disabled
Disabled
Disabled
4000 bytes
Disabled
4000 bytes
Disabled
Disabled
Disabled
Disabled
486
D-Drop
N-None
Level
Actions
low
L
medium
L,D
medium
L,D
low
L
medium
L,D
medium
L
low
L
medium
L,D
info
L
info
L
medium
L,D
medium
L,D
medium
L,D
medium
L,D

Advertisement

Table of Contents
loading

Table of Contents