1.1.1 attack-defense login reauthentication-delay attack-defense login reauthentication-delay命令用来配置Login用户登录失败后重新进行认证的等待时长。 undo attack-defense login reauthentication-delay命令用来恢复缺省情况。 【命令】 attack-defense login reauthentication-delayseconds ...
attack-defense policy policy-name (3) 对所有非受保护IP地址开启SYN-ACK flood攻击防范检测。 syn-ack-flood detect non-specific 缺省情况下,未对任何非受保护IP地址开启SYN-ACK flood攻击防范检测。 (4) 配置SYN-ACK flood攻击防范的全局触发阈值。 syn-ack-flood threshold threshold-value 缺省情况下,SYN-AC...
attack-defense apply policy AtkInterface2#interface GigabitEthernet0/1 port link-mode route combo enable copper#interface GigabitEthernet0/2 port link-mode route description Multiple_Line2 combo enable copper pppoe-client dial-bundle-number 2#interface GigabitEthernet0/3 port link-mode route combo ena...
H3C-华三 攻击检测及防范命令
H3C-华三 攻击检测及防范命令
H3C-攻击防范配置
attack-defense apply policy ···1-1 1.1.2 attack-defense policy ···1-1 1.1.3 blacklist enable ···
undo attack-defense tcp fragment enable # acl number 2000 rule 0 permit source 172.10.10.0 0.0.0.255 # vlan 1 # vlan 2 # domain system access-limit disable state active idle-cut disable self-service-url disable # dhcp server ip-pool vlan2 ...
attack-defense apply policy AtkInterface2 # dhcp上网时外网口配置如下 <H3C>system-view [H3C]interface GigabitEthernet 0/0 [H3C-GigabitEthernet0/0] ip address dhcp-alloc //配置外网口地址为自动获取,当自动获取到地址后会自动生成优先级为70的默认路由 ...
H3C M9000配置笔记 设备管理方式配置: intM-g1/0/0/0//进入管理口并配置IP ipaddress security-zonenametrust//将管理口加入到trust区域 importinterfaceM-g1/0/0/0 aclnu2000//创建ACL并允许合法用户管理 rulepermitsourceX.X.X.X zone-pairsecuritysourcetrustdestinationlocal//配置域间策略,放行trust...