Configuring Defense Against UDP Flood Attacks
Context
If an attacker sends a large number of UDP packets with specified destination port numbers to a target host in a short time, the target host is busy with these UDP packets and cannot process normal services. To prevent UDP flood attacks, enable defense against UDP flood attacks.
The device enabled with defense against UDP flood attacks discards UDP packets with port numbers 7, 13, and 19.
Procedure
- Run system-view
The system view is displayed.
- Run anti-attack udp-flood enable
Defense against UDP flood attacks is enabled.
By default, defense against UDP flood attacks is enabled.
You can also run the anti-attack enable command in the system view to enable attack defense against all attack packets including UDP flood attack packets. - Run commit
The configuration is committed.