
sip-media protocol timeout : 120 (s)
---------------------------------------------
3.10 Configuring the Attack Defense Function
The AR1200-S attack defense function prevents attacks to the CPU. It ensures that the server
operates normally even when it is attacked.
3.10.1 Establishing the Configuration Task
Before configuring the attack defense function, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the data required for the
configuration. This will help you complete the configuration task quickly and accurately.
Applicable Environment
On the AR1200-S, you can enable the attack defense function for the protected area. The
protected area may be zones or IP addresses.
Pre-configuration Tasks
Before configuring the attack defense function, complete the following tasks:
l
Configuring zones and adding interfaces to the zones
l
Configuring the interzone and enabling the firewall function in the interzone
Data Preparation
To configure the attack defense function, you need the following data.
No.
Data
1
Attack type, a specified type or all types
3
Status of the TCP proxy that prevents SYN Flood attacks, including always
enabled, always disabled, or auto enabled (automatically enabled when the session
rate exceeds the threshold)
4
Timeout of blacklist and maximum session rate to prevent scanning attacks (IP
address sweeping and port scanning)
5
Maximum packet length to prevent a large ICMP packet attack
3.10.2 Enabling the Attack Defense Function
Context
Steps 2-19 are optional and can be performed in any sequence. You can select these steps to
defend against different types of attacks.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
67