
l
Enable defense against packet fragment attacks and restrict the rate for sending packet
fragments to 15000 bit/s to prevent packet fragments from attacking the CPU and using
excessive CPU and system resources.
l
Enable defense against flood attacks as follows:
–
Enable defense against SYN flood attacks and restrict the rate for sending TCP SYN
packets to 15000 bit/s to prevent the TCP SYN packets from using excessive CPU
resources.
–
Enable defense against UDP flood attacks to discard the UDP packets sent on specified
ports.
–
Enable defense against ICMP flood attacks and restrict the rate for sending ICMP flood
packets to 15000 bit/s to prevent the ICMP flood packets from using excessive CPU
resources.
Figure 14-1
Networking diagram of configuring Attack Defense
hacker
user
user
VLAN100
VLAN300
VLAN200
RouterB
GE1/0/0
100.111.1.1/24
GE1/0/0
100.111.1.2/24
Internet
RouterA
Configuration Roadmap
The configuration roadmap is as follows:
1.
Configure the IP addresses and routes of each interface to guarantee internetworking.
2.
Enable defense against abnormal packet attacks on Router A.
3.
Enable defense against packet fragment attacks on Router A.
4.
Enable defense against flood attacks on Router A.
Data Preparation
To complete the configuration, you need the following data:
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
14 Configuration of Attack Defense and Application Layer
Association
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
292