1014
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
interface-type interface-number: Specifies an interface by its type and number.
slot slot-number: Specifies a card by its slot number. This option is available only when you specify a
global interface, such as a VLAN interface or tunnel interface. If you do not specify a card, this
commands displays attack detection and prevention statistics for all cards. (Distributed devices in
standalone mode.)
slot slot-number: Specifies an IRF member device by its member ID. This option is available only
when you specify a global interface, such as a VLAN interface or tunnel interface. If you do not
specify a member device, this commands displays attack detection and prevention statistics for all
member devices. (Centralized devices in IRF mode.)
chassis chassis-number slot slot-number: Specifies a card on an IRF member device. The
chassis-number argument represents the member ID of the IRF member device. The slot-number
argument represents the slot number of the card. This option is available only when you specify a
global interface, such as a VLAN interface or tunnel interface. If you do not specify a card, this
commands displays attack detection and prevention statistics for all cards. (Distributed devices in
IRF mode.)
Examples
# (Centralized devices in standalone mode.) Display attack detection and prevention statistics on
interface GigabitEthernet 1/0/1.
<Sysname> display attack-defense statistics interface gigabitethernet 1/0/1
Attack policy name: abc
Scan attack defense statistics:
AttackType AttackTimes Dropped
Port scan 2 23
IP sweep 3 33
Distribute port scan 1 10
Flood attack defense statistics:
AttackType AttackTimes Dropped
SYN flood 1 0
ACK flood 1 0
SYN-ACK flood 3 5000
RST flood 2 0
FIN flood 2 0
UDP flood 1 0
ICMP flood 1 0
ICMPv6 flood 1 0
DNS flood 1 0
HTTP flood 1 0
Signature attack defense statistics:
AttackType AttackTimes Dropped
IP option record route 1 100
IP option security 2 0
IP option stream ID 3 0