287
SIGNAMAX LLC • www.signamax.eu
maxcount
To set the threshold value for detection (default 1000), if the number of
the SYN packets sent to the host received in 1 second exceeds number,
then intercept.
Scan Detection
Overview
Scan detection module can detect the address scan and port scan attack. By default, the
system has a set of threshold values for scan detection. Users also can define the threshold
values of the scan to achieve more careful scan detection. When detecting a scan happens at
an address, users can define to prohibit the access in a period, and it is 15 seconds by default.
At the same time, the system records the scan action of the IP into the log, to facilitate users
analyzing.
Basic Commands
Command
Description
Config mode
scanprotect
To configure the scan detect protection function
config-if-××
clear scanprotect
To clear the present scan information
enable
Note:
The symbol “*” before the command description means that there is the configuration
example to describe the command in details later.
scanprotect
This command is to configure the scan detection function on an interface.
[
no
]
scanprotect interval
{
default
| interval-value
}
addr-limit
{
default
| max-addr-
value
}
port-limit
{
default
| max-port-value
}
ban-timeout
{
default
| max-ban-timeout
}
Syntax
Description
default
To adopt the default value
scanprotect
To enable the scan detection function on the interface
interval
The time interval of scan detection, 1 second by default. That is to say, in
less than 1 second, the number of the scanned addresses is over max-
addr-value or the number of the scanned ports is over max-port-value,
then we could know that the scan attack exists.
addr-limit
To define the maximum addresses can be scanned continuously, 10 by
default.
port-limit
To define the maximum ports can be scanned continuously, 10 by default
Содержание 065-7434
Страница 1: ...24 Port 10 100 L3 Switch Model 065 7434 Configuration Guide Revision A1 ...
Страница 245: ...245 SIGNAMAX LLC www signamax eu Application Example Example of configuring DHCP Snooping ...
Страница 302: ...302 SIGNAMAX LLC www signamax eu Default status no switching interface ...
Страница 368: ......
Страница 655: ...287 SIGNAMAX LLC www signamax eu Sub VLAN members in the system ...