
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
anti-attack fragment
enable
Defense against packet fragment attacks is enabled.
Defense against packet fragment attacks is enabled by default. Thus, you need to configure the
restricted rate only. If defense against packet fragment attacks is disabled, run the command to
enable it.
Step 3
Run:
anti-attack fragment car
cir
cir
The rate of sending packet fragments is restricted.
----End
14.3.3 Checking the Configuration
After configuring defense against fragmented packet attacks, you can view statistics about
defense against fragmented packets on the LPU.
Prerequisites
The configurations of the fragmented packet attack defense are complete.
Procedure
Step 1
Run the
display anti-attck statistics
fragment
command to check the statistics of defense
against packet fragment attacks on the interface board.
----End
Example
After the configuration is complete, run the
display anti-attck statistics
fragment
command
to check the statistics of defense against packet fragment attacks on the interface board.
<Huawei>
display anti-attck statistics fragment
Packets Statistic Information:
-------------------------------------------------------------------------------
AntiAtkType TotalPacketNum DropPacketNum PassPacketNum
(H) (L) (H) (L) (H) (L)
-------------------------------------------------------------------------------
Fragment 0 0 0 0 0 0
-------------------------------------------------------------------------------
14.4 Configuring Flood Attack Defense
Flood attacks include SYN flood attacks, UDP flood attacks, and ICMP flood attacks.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
14 Configuration of Attack Defense and Application Layer
Association
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
286