441
RST flood 1000(default) - - Disabled
FIN flood 1000(default) - - Disabled
UDP flood 1000(default) - - Disabled
ICMP flood 1000(default) - - Disabled
ICMPv6 flood 1000(default) - - Disabled
DNS flood 1000(default) - 53 Disabled
HTTP flood 1000(default) - 80 Disabled
Flood attack defense for protected IP addresses:
Address VPN instance Flood type Thres(pps) Actions Ports
192.168.2.1 -- SYN-FLOOD 5000 L,D -
If the device receives TCP flag attack packets or scanning attack packets that are destined for the
device, the device outputs logs. If the device receives TCP SYN flood attack packets that are
destined for the protected IP address, the device outputs logs and drops the attack packets. If the
device receives TCP SYN flood attack packets that are destined for the device but not to the
protected IP address, the device outputs logs.
# Display the attack detection and prevention statistics.
[Switch] display attack-defense statistics local
Attack policy name: a1
Slot 1:
Scan attack defense statistics:
AttackType AttackTimes Dropped
Port scan 4 0
Flood attack defense statistics:
AttackType AttackTimes Dropped
No flood attacks detected.
Signature attack defense statistics:
AttackType AttackTimes Dropped
TCP invalid flags 116 0
TCP null flag 709 0
TCP all flags 251 0
TCP SYN-FIN flags 46 0
TCP FIN only flag 130 0
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...