403
RAWIP sessions : 0
RAWIP session establishment rate : 0/s
[Router-GigabitEthernet1/0/1] display flow-statistics statistics interface
gigabitethernet 1/0/1 outbound
Flow Statistics Information
------------------------------------------------------------
Interface : GigabitEthernet1/0/1
------------------------------------------------------------
Total number of existing sessions : 13676
Session establishment rate : 2735/s
TCP sessions : 0
Half-open TCP sessions : 0
Half-close TCP sessions : 0
TCP session establishment rate : 0/s
UDP sessions : 13676
UDP session establishment rate : 2735/s
ICMP sessions : 0
ICMP session establishment rate : 0/s
RAWIP sessions : 0
RAWIP session establishment rate : 0/s
The output shows that on GigabitEthernet 1/0/1, there is a large number of UDP packets destined for
10.1.1.2, and the session establishment rate has exceeded the specified threshold. Therefore, determine
that the server is under a UDP flood attack. Use
display attack-defense statistics
to view the related
statistics collected after the UDP flood protection function takes effect.
Configuring TCP proxy
Network requirements
Configure the TCP proxy function on the router to protect internal servers from SYN flood attacks.
Configure the function to work in bidirectional mode.
Figure 139
Network diagram for configuring TCP proxy
Configuration procedure
# Configure IP addresses for interfaces. (Omitted)
# Create attack protection policy 1.
<Router> system-view