436
A switch uses hardware to implement packet forwarding and uses software to process packets if the
packets are destined for the switch. The software does not provide any attack defense features, so
you must apply an attack defense policy to the switch to prevent attacks aimed at the switch.
To apply an attack defense policy to the device:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Apply an attack defense
policy to the device.
attack-defense local apply
policy
policy-name
By default, no attack defense policy
is applied to the device.
Enabling log non-aggregation for single-packet attack events
Log aggregation aggregates multiple logs generated during a period of time and sends one log. Logs
that are aggregated must have the following attributes in common:
•
Attacks are destined for the device.
•
Attack type.
•
Attack prevention action.
•
Source and destination IP addresses.
•
VPN instance to which the victim IP address belongs.
As a best practice, do not disable log aggregation. A large number of logs will consume the display
resources of the console.
To enable log non-aggregation for single-packet attack events:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable log non-aggregation
for single-packet attack
events.
attack-defense signature log
non-aggregate
By default, log non-aggregation is
disabled for single-packet attack
events.
Configuring TCP fragment attack prevention
The TCP fragment attack prevention feature detects the length and fragment offset of received TCP
fragments and drops attack TCP fragments.
TCP fragment attack prevention takes precedence over single-packet attack prevention. When both
are used, incoming TCP packets are processed first by TCP fragment attack prevention and then by
the single-packet attack defense policy.
To configure TCP fragment attack prevention:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable TCP fragment attack
prevention.
attack-defense tcp fragment
enable
By default, TCP fragment attack
prevention is enabled.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...