429
Use
undo defense udp-flood enable
to restore the default.
Syntax
defense udp-flood enable
undo defense udp-flood enable
Default
UDP flood attack protection is disabled.
Views
Attack protection policy view
Default command level
2: System level
Examples
# Enable UDP flood attack protection in attack protection policy 1.
<Sysname> system-view
[Sysname] attack-defense policy 1
[Sysname-attack-defense-policy-1] defense udp-flood enable
Related commands
•
defense udp-flood action drop-packet
•
defense udp-flood rate-threshold
•
defense udp-flood ip
•
display attack-defense policy
defense udp-flood ip
Use
defense udp-flood ip
to configure the action and silence thresholds for UDP flood attack
protection of a specific IP address.
Use
undo defense udp-flood
ip
to remove the configuration.
Syntax
defense udp-flood ip
ip-address
rate-threshold high
rate-number
[
low
rate-number
]
undo defense udp-flood
ip
ip-address
[
rate-threshold
]
Default
No UDP flood attack protection thresholds are configured for an IP address.
Views
Attack protection policy view
Default command level
2: System level
Parameters
ip-address
: IP address to be protected. This IP address cannot be a broadcast address, 127.0.0.0/8,
a class D address, or a class E address.
high
rate-number
: Sets the action threshold for UDP flood attack protection of the specified IP
address. The
rate-number
argument indicates the number of UDP packets sent to the specified IP
address per second and is in the range of 1 to 64000. With the UDP flood attack protection enabled,
the device enters attack detection state. When the device detects that the sending rate of UDP