
Applicable Environment
To prevent network devices from being attacked by the packets of idle protocols and to prevent
the network from running busily, overhigh usage of CPU, and DoS attack, the application layer
association is required and the protocol module must be disabled. In this way, the protocol
packets are discarded without being sent to the CPU. Thus, the CPU works normally.
Pre-configuration Tasks
Before configuring application layer association, complete the following tasks:
l
Setting the link layer protocol parameters (and the IP address) for the interface to make the
status of link protocol Up
Data Preparation
To configure association layer association, you need the following data.
No.
Data
1
Protocols to be enabled/disabled
2
Packet policy that does not match the application layer association module
14.5.2 Configuring Application Layer Association
Enabling of the application layer association module depends on whether a protocol is enabled.
Whether a packet that mismatches the application layer association module is forwarded or
discarded depends on the configuration of the device.
Context
The application layer association module uses the switch to control whether the application layer
association is enabled. If the protocol is enabled, the packets of the protocol are sent. If the
protocol is disabled, the packets of the protocol are directly discarded.
To prevent the attacks from the packets of idle protocols, the protocol module must be disabled.
If the protocol is enabled, which cannot filter invalid packets, use the rate restriction function to
restrict the rate of sending packets and protect the CPU from being attacked.
Do as follows on the router:
Procedure
Step 1
Run the
system-view
command to enter the system view.
Step 2
For all the protocols and functions that match the application layer association, enable the
necessary protocols and disable the idle protocols to prevent attacks on the CPU.
Step 3
(Optional) Run the
application-apperceive default drop
to discard the packets if no application
layer association policy is found.
----End
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
14 Configuration of Attack Defense and Application Layer
Association
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
290