
The rate of sending TCP SYN packets is restricted.
----End
14.4.3 Configuring Defense Against UDP Flood Attacks
The major measure to defend UDP flood attacks is to limit the rate of UDP packets.
Context
Do as follows on the router:
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
anti-attack udp-flood
enable
Defense against UDP flood attacks is enabled.
Defense against UDP flood attacks is enabled by default. If defense against UDP flood attacks
is disabled, run the command to enable it.
----End
14.4.4 Configuring Defense Against ICMP Flood Attacks
The major measure to defend ICMP flood attacks is to limit the rate of ICMP packets.
Context
Configure router as follows:
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
anti-attack icmp-flood
enable
Defense against ICMP flood attacks is enabled.
Defense against ICMP flood attacks is enabled by default. Thus, you need to configure the
restricted rate only. If defense against ICMP flood attacks is disabled, run the command to enable
it.
Step 3
Run:
anti-attack icmp-flood car
cir
cir
The rate of sending ICMP flood packets is restricted.
----End
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
14 Configuration of Attack Defense and Application Layer
Association
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
288