INS_CNXE2GE2TX8MSPOE 11 Jan 2021 PAGE 135
INSTALLATION AND OPERATION MANUAL
CNXE2GE2TX8MSPOE
TECH SUPPORT: 1.888.678.9427
DDoS Prevention
This page provides DDOS Prevention configurations. The switch can monitor ingress packets,
and perform actions when DDOS attack occurred on this port. You can configure the setting to
achieve maximum protection.
Label
Description
Mode
Enables or disables DDOS prevention of the port
Sensibility
Indicates the level of DDOS detection. Possible levels are:
Low: low sensibility
Normal: normal sensibility
Medium: medium sensibility
High: high sensibility
Packet Type
Indicates the types of DDoS attack packets to be monitored.
Possible types are:
RX Total: all ingress packets
RX Unicast: unicast ingress packets
RX Multicast: multicast ingress packets
RX Broadcast: broadcast ingress packets
TCP: TCP ingress packets
UDP: UDP ingress packets
Socket Number
If packet type is UDP (or TCP), please specify the socket number here. The
socket number can be a range, from low to high. If the socket number is only
one, please fill the same number in the low and high fields.
Filter
If packet type is UDP (or TCP), please choose the socket direction (Destination/
Source).
Action
Indicates the action to take when DDOS attacks occur.
Possible actions are:
---: no action
Blocking 1 minute: blocks the forwarding for 1 minute and log the event
Blocking 10 minute: blocks the forwarding for 10 minutes and log the event
Blocking: blocks and logs the event
Shunt Down the Port: shuts down the port (No Link) and logs the event
Only Log it: simply logs the event
Reboot Device: if PoE is supported, the device can be rebooted. The event will
be logged.