
14.4.1 Establishing the Configuration Task
This section describes the applicable environment, required tasks, and data for configuring
defense against flood attacks.
Applicable Environment
Different types of attacks on a network cause network devices overused, and even failed, thus
affecting network services.
To prevent the network devices from being attacked and to ensure normal network services,
defense against flood attacks must be configured.
Pre-configuration Tasks
Before configuring defense against flood attacks, complete the following tasks:
l
Setting the link layer protocol parameters (and the IP address) for the interface to make the
status of link protocol Up
Data Preparation
To configure defense against flood attacks, you need the following data:
No.
Data
1
Rate restricted by TCP SYN packets and rate restricted by ICMP flood packets
14.4.2 Configuring Defense Against SYN Flood Attacks
The major measure to defend SYN flood attacks is to limit the rate of TCP SYN packets.
Context
Do as follows on the router:
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
anti-attack tcp-syn
enable
Defense against SYN flood attacks is enabled.
Defense against SYN flood attacks is enabled by default. Thus, you need to configure the
restricted rate only. If defense against SYN flood attacks is disabled, run the command to enable
it.
Step 3
Run:
anti-attack tcp-syn car
cir
cir
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
14 Configuration of Attack Defense and Application Layer
Association
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
287