531
A blacklist entry with an aging time is not saved to the configuration file and cannot survive a reboot.
You can use the
display blacklist ipv6
command to display all effective IPv6 blacklist entries that
are manually added.
Examples
# Add a blacklist entry for IPv6 address 2012::12:25 and set the aging time to 10 minutes for the
entry.
<Sysname> system-view
[Sysname] blacklist ipv6 2012::12:25 timeout 10
Related commands
blacklist enable
blacklist global enable
blacklist ip
blacklist logging enable
Use
blacklist logging enable
to enable logging for the blacklist feature.
Use
undo blacklist logging enable
to disable logging for the blacklist feature.
Syntax
blacklist logging enable
undo blacklist logging enable
Default
Logging is disabled for the blacklist feature.
Views
System view
Predefined user roles
network-admin
mdc-admin
Usage guidelines
With logging enabled for the blacklist feature, the system outputs logs in the following situations:
•
A blacklist entry is manually added.
•
A blacklist entry is dynamically added by the scanning attack detection feature.
•
A blacklist entry is manually deleted.
•
A blacklist entry ages out.
A blacklist log records the following information:
•
Source IP address of the blacklist entry.
•
VPN instance name.
•
Reason for adding or deleting the blacklist entry.
•
Aging time for the blacklist entry.
Examples
# Enable logging for the blacklist feature.
<Sysname> system-view
[Sysname] blacklist logging enable
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...