Configuration Guide
DoS Protection Configuration
Configure Ingress Filtering to Defend Against DoS Attack
Default configuration
The ingress filtering for defending against DoS attacks is disabled on all network
interfaces.
Precautions
Only layer-3 interfaces with network address can support ingress filtering for
defending against DoS attacks.
By enabling defeat DoS based ingress filtering on the designated layer-3 interface,
the system will automatically establish the corresponding ACL for the network
interface to restrict the access of disguised source IP, and apply the ACL to the
ingress of layer-3 interface.
For example: The network address on SVI 1 is 192.168.5.1/24. If “ip deny
spoofing-
source” is configured in the interface configuration mode, the following ACL
will be generated automatically and applied to this interface.
permit 192.168.5.0 0.0.0.255
permit host 0.0.0.0 (This ACE permits the access of DHCP requests with source
address being 0.0.0.0)
deny any
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...