No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Configuration Guide - Security

S9300, S9300E, and S9300X V200R011C10

This document describes the configurations of Security, including ACL, reflective ACL, local attack defense, MFF, attack defense, traffic suppression and storm control, ARP security, port security, DHCP snooping, ND snooping, PPPoE+, IPSG, SAVI, URPF, keychain, separating the management plane from the service plane, security risks.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Setting the Rate Threshold for Port Attack Defense

Setting the Rate Threshold for Port Attack Defense

Context

After port attack defense is enabled on a port, the device calculates the rate of affected protocol packets received by the port. If the packet rate exceeds the threshold, the device considers that an attack occurs. Then the device traces the source and limits the rate of attack packets on the port, and records a log. The device moves the packets within the protocol rate limit to a low-priority queue waiting for CPU processing and discards the excess packets. (The protocol rate limit is the CPCAR in an attack defense policy. For description about CPCAR, see Configuring a Rule for Sending Packets to the CPU.)

You need to set an appropriate rate threshold for port attack defense according to service requirements. If the CPU fails to process many protocol packets promptly after port attack defense is enabled, set a large packet rate threshold. If the CPU is busy processing the packets of a protocol, set a small rate threshold for this protocol to avoid impact on other services.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run cpu-defend policy policy-name

    The attack defense policy view is displayed.

  3. Run auto-port-defend protocol { all | arp-request | arp-reply | dhcp | icmp | igmp | ip-fragment } threshold threshold

    The protocol rate threshold for port attack defense is set.

    The following table lists the default protocol rate thresholds for different protocols.

    Packet Type

    Rate Threshold

    arp-request

    The default value for an LPU is 60 pps, and the default value for a main control unit varies depending on the model of main control unit:

    • S9300: 30 pps for SRUA, SRUB, and MCUA; 120 pps for SRUH, SRUK, and SRUE
    • S9300E: 30 pps for MCUA; 60 pps for SRUC and SRUD
    • S9300X: 120 pps
    arp-reply

    The default value for an LPU is 60 pps, and the default value for a main control unit varies depending on the model of main control unit:

    • S9300: 30 pps for SRUA, SRUB, and MCUA; 120 pps for SRUH, SRUK, and SRUE
    • S9300E: 30 pps for MCUA; 60 pps for SRUC and SRUD
    • S9300X: 120 pps
    dhcp

    The default value for an LPU is 60 pps, and the default value for a main control unit varies depending on the model of main control unit:

    • S9300: 30 pps for SRUA, SRUB, and MCUA; 120 pps for SRUH, SRUK, and SRUE
    • S9300E: 30 pps for MCUA; 60 pps for SRUC and SRUD
    • S9300X: 120 pps
    icmp

    The default value for an LPU is 60 pps, and the default value for a main control unit varies depending on the model of main control unit:

    • S9300: 60 pps for SRUA, SRUB, and MCUA; 120 pps for SRUH, SRUK, and SRUE
    • S9300E: 60 pps
    • S9300X: 120 pps
    igmp

    The default value for an LPU is 60 pps, and the default value for a main control unit varies depending on the model of main control unit:

    • S9300: 60 pps for SRUA, SRUB, and MCUA; 120 pps for SRUH, SRUK, and SRUE
    • S9300E: 60 pps
    • S9300X: 120 pps
    ip-fragment

    30 pps

Translation
Download
Updated: 2019-04-01

Document ID: EDOC1000178410

Views: 130293

Downloads: 25

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next