459
Step Command
Remarks
logging
} * ]
Configuring a SYN-ACK flood attack defense policy
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter attack defense policy
view.
attack-defense policy
policy-name
N/A
3.
Enable global SYN-ACK
flood attack detection.
syn-ack-flood detect
non-specific
By default, global SYN-ACK flood
attack detection is disabled.
4.
Set the global trigger
threshold for SYN-ACK
flood attack prevention.
syn-ack-flood threshold
threshold-value
The default setting is 1000.
5.
Specify global actions
against SYN-ACK flood
attacks.
syn-ack-flood action
{
drop
|
logging
} *
By default, no global action is
specified for SYN-ACK flood
attacks.
6.
Configure IP
address-specific SYN-ACK
flood attack detection.
syn-ack-flood
detect
{
ip
ip-address
|
ipv6 ipv6-address
}
[
vpn-instance
vpn-instance-name
] [
threshold
threshold-value
] [
action
{
drop
|
logging
} * ]
By default, IP address-specific
SYN-ACK flood attack detection is
not configured.
Configuring a FIN flood attack defense policy
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter attack defense policy
view.
attack-defense policy
policy-name
N/A
3.
Enable global FIN flood
attack detection.
fin-flood detect non-specific
By default, global FIN flood attack
detection is disabled.
4.
Set the global trigger
threshold for FIN flood
attack prevention.
fin-flood threshold
threshold-value
The default setting is 1000.
5.
Specify global actions
against FIN flood attacks.
fin-flood action
{
drop
|
logging
} *
By default, no global action is
specified for FIN flood attacks.
6.
Configure IP
address-specific FIN flood
attack detection.
fin-flood
detect
{
ip ip-address
|
ipv6 ipv6-address
}
[
vpn-instance
vpn-instance-name
] [
threshold
threshold-value
] [
action
{
drop
|
logging
} * ]
By default, IP address-specific FIN
flood attack detection is not
configured.
Configuring an RST flood attack defense policy
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter attack defense policy
view.
attack-defense policy
policy-name
N/A