
l
Run the
display cpu-defend configuration
[
packet-type
packet-type
] {
all
|
slot
slot-
id
|
sru
} command to check the rate limit configuration for protocol packets sent to the
CPU.
----End
9.5 Maintaining the Attack Defense Policy
This section describes how to maintain the attack defense policy.
9.5.1 Clearing Statistics on Packets Sent to the CPU
This section describes how to clear statistics on packets sent to the CPU.
Procedure
l
Run the
reset cpu-defend statistics
[
packet-type
packet-type
] command to clear statistics
on packets sent to the CPU.
----End
9.5.2 Clearing Attack Source Information
This section describes how to clear attack source information.
Procedure
l
Run the
reset auto-defend attack-source
command to clear attack source information.
----End
9.6 Configuration Examples
This section provides attack defense policy configuration examples.
9.6.1 Example for Configuring an Attack Defense Policy
This section provides an example for configuring an attack defense policy.
Networking Requirements
As shown in
, users on different LANs access the Internet through RouterA. To locate
attacks on RouterA, attack source tracing needs to be configured to trace the attack source. The
problems in this scenario are as follows:
l
A user on the network segment Net1 often attacks RouterA.
l
Attackers send a large number of ARP Request packets, resulting in CPU performance
deterioration.
l
The administrator needs to upload files to RouterA using FTP. An FTP connection between
the administrator's host and RouterA needs to be set up.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
9 Local Attack Defense Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
178