370
Configuring connection limit
An internal user who initiates a large quantity of connections to external networks in a short period of
time occupies large amounts of system resources of the device, making other users unable to access
network resources normally. An internal server that receives large numbers of connection requests within
a short time cannot process them in time or accept other normal connection requests. To avoid such
situations, configure a connection limit policy to collect statistics on connections and limit the number of
connections.
Configuration task list
Task Remarks
Creating a connection limit policy
Required
Configuring the connection limit policy
Configuring an IP address-based
connection limit rule
Required
Applying the connection limit policy
Required
Creating a connection limit policy
A connection limit policy comprises a set of connection limit rules, which define the valid range and
parameters for the policy.
To create a connection limit policy:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Create a connection limit
policy and enter its view.
connection-limit policy
policy-
number
Required
Configuring the connection limit policy
A connection limit policy contains one or more connection limit rules, each specifying an object or range
for the limit. A user connection matching a rule is limited based on the parameters in the rule.
Configuring an IP address-based connection limit rule
An IP address-based connection limit rule allows you to limit the number of connections from a specified
source IP address to a specified destination IP address.
The limit rules are matched in ascending order of rule ID. When configuring connection limit rules for a
policy, check the rules and their order carefully. HP recommends that you arrange the rules in ascending
order of granularity and range.
An IP address-based connection limit rule can be any of these types: