
ssh-server Enabled 128 4
sslvpn Enabled 4096 3
stp Enabled 96 3
tcp Enabled 128 2
telnet-client Enabled 128 4
telnet-server Enabled 128 4
ttl-expired Enabled 256 1
udp-helper Disabled 16 2
unknown-multicast Enabled 128 1
unknown-packet Enabled 256 1
voice Enabled 256 4
vrrp Disabled 256 3
-----------------------------------------------------------------
# The log for attack source tracing of Net1 indicates that attack source tracing has taken effect.
Dec 18 2010 09:55:50-05:13 AR1200-S %%01SECE/4/USER_ATTACK(l)[0]:User attack
occurred.(Slot=MPU, SourceAttackInterface=Ethernet0/0/1, OuterVlan/
InnerVlan=0/0, UserMacAddress=0001-c0a8-0102, AttackPackets=48 packets per
second)
# View the statistics on packets sent to the SRU. The discarded packets indicate that the rate
limit is set for ARP Request packets.
<Huawei>
display cpu-defend statistics
-----------------------------------------------------------------------
Packet Type Pass Packets Drop Packets
-----------------------------------------------------------------------
8021X 0 0
arp-miss 5 0
arp-reply 8090 0
arp-request 1446576 127773
bfd 0 0
bgp 0 0
bgp4plus 0 0
dhcp-client 879 0
dhcp-server 0 0
dhcpv6-reply 0 0
dhcpv6-request 0 0
dlsw 0 0
dns 4 0
fib-hit 0 0
fr 0 0
ftp-client 0 0
ftp-server 0 0
fw-dns 0 0
fw-ftp 0 0
fw-http 0 0
fw-rtsp 0 0
fw-sip 0 0
gre-keepalive 0 0
gvrp 0 0
hdlc 0 0
http-client 0 0
http-server 0 0
hw-tacacs 0 0
icmp 59 0
icmpv6 224 0
igmp 539 0
ip-option 0 0
ipsec-ike 0 0
ipsec-isa 0 0
ipsec-osa 0 0
isis 70252 0
isisv6 0 0
l2tp 0 0
lacp 0 0
lldp 0 0
nd 358 0
nd-miss 0 0
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
9 Local Attack Defense Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
182