Configuring Host Attack Defense
Context
After the ssh server acl, telnet server acl, ftp server acl, or snmp-agent acl command is configured, a switch forwards SSH, Telnet, FTP, or SNMP packets to the CPU and matches these packets against software ACLs. When host attack defense is enabled, the switch matches these packets against hardware ACLs. If packets match an ACL with a deny action, the switch directly discards the packets and will no longer forward such packets to the CPU.