417
Syntax
attack-defense tcp fragment enable
undo attack-defense tcp fragment enable
Default
TCP fragment attack protection is disabled.
Views
System view
Default command level
2: System level
Usage guidelines
This command enables the device to drop attack TCP fragments to prevent TCP fragment attacks.
Examples
# Disable TCP fragment attack protection.
<Sysname> System-view
[Sysname] undo attack-defense tcp fragment enable
blacklist enable
Use
blacklist enable
to enable the blacklist function.
Use
undo blacklist enable
to restore the default.
Syntax
blacklist enable
undo blacklist enable
Default
The blacklist function is disabled.
Views
System view
Default command level
2: System level
Usage guidelines
After the blacklist function is enabled, you can add blacklist entries manually or configure the device
to add blacklist entries automatically. The auto-blacklist function must cooperate with the scanning
attack protection function or the user login authentication function. For configuration information
about scanning attack protection, see the
defense scan add-to-blacklist
command.
Examples
# Enable the blacklist function.
<Sysname> system-view
[Sysname] blacklist enable
Related commands
•
defense
scan
•
display attack-defense policy