
9.1 Local Attack Defense Overview
This section describes the background and functions of local attack defense.
On a network, a large number of packets including valid packets and malicious attack packets
need to be delivered to the CPU. The malicious attack packets will affect other services or even
interrupt the system. When the AR1200-S processes excess valid packets, the CPU usage
becomes high. As a result, the CPU performance deteriorates and services are interrupted.
To protect the CPU and ensure that it can process services, the AR1200-S provides the local
attack defense function. The local attack defense functions protect the AR1200-S against attacks,
ensure service transmission in the case of attacks, and minimize the impact on the services in
the case of attacks by limiting the rate of packets sent to the CPU.
9.2 Local Attack Defense Features Supported by the
AR1200-S
This section describes local attack defense features supported by the AR1200-S.
Attack Defense Policies Supported by the AR1200-S
The AR1200-S supports the default attack defense policy. The default attack defense policy
defines the rate limit and priority for protocol packets, and defines the rate limit for all the packets
sent to the CPU. It is applied to all the boards by default, and cannot be modified or deleted.
Attack defense policies can be created on the AR1200-S. The configuration in a user-defined
attack defense policy overrides the configuration in the
default
attack defense policy. If no
parameter is configured in the user-defined attack defense policy, the configuration in the
default
attack defense policy is used.
NOTE
An attack defense policy is invalid for the protocol packets sent from the 3G Cellular interface to the CPU of
the SRU.
NOTE
On the AR1220, an attack defense policy is invalid for Layer 3 protocol packets sent from the LAN-side LPU
to the CPU of the SRU.
Attack Defense Functions Supported by the AR1200-S
Attack source tracing and CPU attack defense can be configured in the same attack defense
policy on the AR1200-S.
Attack source tracing checks attack packets sent to the CPU and notifies the administrator by
sending logs or alarms so that the administrator can take measures to defend against attacks. For
example, the administrator can add the possible attack source to a blacklist. Attack source tracing
provides the following functions:
l
Attack source check
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
9 Local Attack Defense Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
169