
l
Most LAN users obtain IP addresses using DHCP, whereas RouterA does not first process
DHCP Client packets sent to the CPU.
l
The Telnet server is not enabled on RouterA, whereas RouterA often receives a large
number of Telnet packets.
Configurations should be performed on RouterA to solve the preceding problems.
Figure 9-1
Networking diagram of attack defense policy configurations
RouterA
Ethe
rnet0
/0/1
Etherne
t0/0/2
Net1: 1.1.1.0/24
Net2: 2.2.2.0/24
Internet
Net3: 3.3.3.0/24
Et
he
rn
et
0/
0/
3
RouterB
Configuration Roadmap
The configuration roadmap is as follows:
1.
Configure a blacklist and add attackers on the network segment Net1 to the blacklist to
prevent users on Net1 from accessing the network.
2.
Configure the rate limit for ARP Request packets sent to the CPU.
3.
Configure active link protection (ALP) for FTP so that file data can be transmitted between
the administrator's host and RouterA.
4.
Configure a high priority for DHCP Client packets so that RouterA first processes DHCP
Client packets sent to the CPU.
5.
Configure application layer association for Telnet so that RouterA discards the received
Telnet packets.
Data Preparation
To complete the configuration, you need the following data:
l
Name of the attack defense policy: devicesafety
l
Threshold for attack source tracing: 50 pps
l
MAC address of the attacker: 0001-c0a8-0102
l
ACL number: 4001
l
Blacklist ID: 1
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
9 Local Attack Defense Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
179