392
Complete the following tasks to configure attack detection and protection:
Task Remarks
Configuring attack
protection functions for
Creating an attack protection policy
Required
Configuring a single-packet attack
protection policy
Required
Configure one or more
policies as needed
Configuring a scanning attack
protection policy
Configuring a flood attack protection
policy
Applying an attack protection policy to an interface
Required
Optional
Configuring the blacklist function
Optional
Enabling traffic statistics on an interface
Optional
Configuring attack protection functions for an
interface
Creating an attack protection policy
Before configuring attack protection functions for an interface, you must create an attack protection
policy and enter its view. In attack protection policy view, define one or more signatures used for attack
detection and specify the corresponding protection measures.
When creating an attack protection policy, also specify an interface so that the interface uses the policy
exclusively.
To create an attack protection policy:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Create an attack protection
policy and enter attack
protection policy view.
attack-defense policy
policy-
number
[
interface
interface-type
interface-number
]
Required.
By default, no attack protection
policy is created.
Configuring an attack protection policy
In an attack protection policy, specify the signatures for attack detection and the corresponding
protection measures according to the security requirements of your network.
Different types of attack protection policies have different configurations, which are described below in
terms of single-packet attacks, scanning attacks, and flood attacks.