
9.4.8 Applying the Attack Defense Policy
An attack defense policy takes effect only when it is applied to a board.
Prerequisites
To protect session-based application layer data, including data of HTTP Sessions, FTP sessions
andand ensure non-stop transmission of these services when attacks occur, enable active link
protection (ALP) before you create an attack defense policy.
Context
An attack defense policy can be applied to the SRU, all the LAN-side LPUs, or to the specified
LAN-side LPU in the system view.
NOTE
If the attack defense policy is applied to an LAN-side LPU or SRU, it takes effect for only the packets sent
to the CPU of the LAN-side LPU or SRU.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
(Optional) Run:
cpu-defend application-apperceive
[
ftp
|
http
]
enable
ALP is enabled.
NOTE
By default, ALP is enabled for FTP and HTTP
Step 3
Run:
cpu-defend-policy
policy-name
[
global
|
slot
slot-id
]
The attack defense policy is applied.
If
global
or
slot
is not specified, the attack defense policy is applied to the SRU. If
global
is
specified, the attack defense policy is applied to all LAN-side LPUs.If
slot
is specified, the attack
defense policy is applied to a specified LAN-side LPU.
----End
9.4.9 Checking the Configuration
This section describes how to check the CPU attack defense configuration.
Procedure
l
Run the
display cpu-defend policy
[
policy-name
] command to check the attack defense
policy.
l
Run the
display cpu-defend statistics
[
packet-type
packet-type
] command to check the
statistics on packets sent to the CPU.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
9 Local Attack Defense Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
177