816
Syntax
blacklist global enable
undo blacklist global enable
Default
The global blacklist feature is disabled.
Views
System view
Predefined user roles
network-admin
Usage guidelines
If you enable the global blacklist feature, the blacklist feature is enabled on all interfaces.
Examples
# Enable the global blacklist feature.
<Sysname> system-view
[Sysname] blacklist global enable
Related commands
blacklist enable
blacklist ip
blacklist ip
Use
blacklist ip
to add an IPv4 blacklist entry.
Use
undo blacklist ip
to delete an IPv4 blacklist entry.
Syntax
blacklist ip
source-ip-address
[
vpn-instance
vpn-instance-name
]
[
ds-lite-peer
ds-lite-peer-address
]
[
timeout minutes
]
undo blacklist ip source-ip-address
[
vpn-instance vpn-instance-name
]
[
ds-lite-peer
ds-lite-peer-address
]
Default
No IPv4 blacklist entries exist.
Views
System view
Predefined user roles
network-admin
Parameters
source-ip-address
: Specifies an IPv4 address for the blacklist entry. Packets sourced from this
address will be dropped.
vpn-instance vpn-instance-name
: Specifies the MPLS L3VPN instance to which the blacklist
belongs. The
vpn-instance-name
argument is a case-sensitive string of 1 to 31 characters. Do not
specify this option if the blacklist is on the public network.
ds-lite-peer
ds-lite-peer-address
: Specifies the IPv6 address of the B4 element of the DS-Lite tunnel
that transmits packets from the blacklisted IPv4 address.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...