Virus Throttling
Basic Connection-Rate Filtering Configuration
Configuring the Per-Port Filtering Mode
Syntax:
filter connection-rate <
port-list
> < notify-only | throttle | block >
no filter connection-rate <
port-list
>
Configures the per-port policy for responding to detection of a
relatively high number of inbound, routed IP connection
attempts from a given source. The level at which the switch
detects such traffic depends on the sensitivity setting config
ured by the
connection-rate-filter sensitivity
command (page
3-12). (Note: You can use connection-rate ACLs to create excep
tions to the configured filtering policy. See “Configuring and
Applying Connection-Rate ACLs” on page 3-20.)
The
no
form of
the command disables connection-rate filtering on the ports in
#
<
port-list
>
.
notify-only:
If the switch detects a relatively high number of
routed IP connection attempts from a specific host,
notify-only
generates an Event Log message. Sends a similar message to
any SNMP trap receivers configured on the switch.
throttle:
If the switch detects a relatively high number of routed
IP connection attempts from a specific host, this option gener
ates the
notify-only
messaging and also blocks all routed traffic
inbound from the offending host for a penalty period. After the
penalty period, the switch allows routed traffic from the offend
ing host to resume, and re-examines the traffic. If the suspect
behavior continues, the switch again blocks the routed traffic
from the offending host and repeats the cycle. For the penalty
periods, refer to table 9-1, below.
block:
If the switch detects a relatively high number of routed
IP connection attempts from a specific host, this option gener
ates the
notify-only
messaging and also blocks all routed and
switched traffic inbound from the offending host.
Table 9-1.
Throttle Mode Penalty Periods
Throttle Mode
Frequency of IP
Connection Requests
from the Same Source
Mean Number of New
Destination Hosts in the
Frequency Period
Penalty Period
Low
< 0.1 second
54
< 30 seconds
Medium
< 1.0 second
37
30 - 60 seconds
High
< 1.0 second
22
60 - 90 seconds
Aggressive
< 1.0 second
15
90 - 120 seconds
3-13
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......