
l
Level 2: The AR1200-S limits the rate of packets sent to the CPU based on the protocol
type to prevent excess packets of a particular protocol from being sent to the CPU.
l
Level 3: The AR1200-S schedules packets sent to the CPU based on the protocol priority
to ensure that packets with higher protocol priorities are processed first.
l
Level 4: The AR1200-S uniformly limits the rate of packets sent to the CPU and randomly
discards the excess packets to ensure CPU security.
Active link protection (ALP) protects session-based application layer data, including data of
HTTP Sessions, FTP sessions. It ensures non-stop transmission of these services when attacks
occur.
Pre-configuration Tasks
Before configuring an attack defense policy, complete the following task:
l
Connecting interfaces and setting the physical parameters of interfaces so that the physical
layer is Up
Data Preparation
To configure an attack defense policy, you need the following data.
No.
Data
1
Name of an attack defense policy
2
(Optional) Description of an attack defense policy
3
(Optional) ACL rule and number in the blacklist
4
(Optional) Rate limit for packets sent to the CPU
5
(Optional) Priority of protocol packets
6
(Optional) Rate limit for all the packets sent to the CPU
7
(Optional) ALP rate limit
8
Number of the LPU to which the attack defense policy is applied
9.4.2 Creating an Attack Defense Policy
This section describes how to create an attack defense policy.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
cpu-defend policy
An attack defense policy is created and the attack defense policy view is displayed.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
9 Local Attack Defense Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
173