Configuration Guide
NFPP Configuration
It prompts the following message when the IP scan was detected:
%NFPP_IP_GUARD-4-SCAN:
Host<IP=1.1.1.1,
MAC=
N/A,port=Gi4/1,VLAN=1> was detected. (2009-07-01 13:00:00)
The following example shows the describing information included in the sent
TRAP messages:
IP scan from host< IP=1.1.1.1, MAC= N/A,port=Gi4/1,VLAN=1> was detected.
Caution
It sets a policy to the hardware when isolating the attackers.
When the hardware resources have been exhausted, it
prompts the message to inform the administrator.
When it fails to allocate the memory to the detected
attackers,
it
prompts
the
message
like
“
%NFPP_IP_GUARD-4-NO_MEMORY: Failed to alloc memory.
”
to inform the administrator.
This section shows the administrator how to configure the host-based rate-limit
and attack detection in the nfpp configuration mode and in the interface
configuration mode:
Command
Function
Ruijie#
configure terminal
Enter the global configuration mode.
Ruijie(config)#
nfpp
Enter the nfpp configuration mode.
Ruijie(config-nfpp)#
ip-guard
rate-limit
per-src-ip
pps
Configure the ip-guard rate-limit,
ranging from 1 to 9999, 20 by default.
per-src-ip
: detect the hosts based on
the source IP address/VID/port;
Ruijie(config)#
ip-guard attack-threshold
per-src-ip
pps
Configure the ip-guard attack
threshold, ranging from 1 to 9999, 20
by default. When the IP packet number
sent from a host exceeds the attack
threshold, the attack is detected and
IP-guard isolates the host, records the
message and sends the TRAP packet.
per-src-ip
: detect the hosts based on
the source IP address/VID/port;
Summary of Contents for RG-S2900G-E Series
Page 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Page 91: ...Configuration Guide Configuring PoE Configuration ...
Page 133: ...Configuration Guide EEE Configuration ...
Page 319: ...Configuration Guide QinQ Configuration ...
Page 408: ......
Page 409: ...IP Routing Configuration 1 Static Route Configuration ...
Page 412: ......
Page 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Page 757: ......
Page 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Page 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Page 901: ...Configuration Guide ERSPAN Configuration ...
Page 902: ...Web based Configuration 1 Web based Configuration ...