571
display attack-defense { ack-flood | dns-flood | fin-flood | flood | http-flood | icmp-flood | rst-flood
| syn-ack-flood | syn-flood | udp-flood } statistics ip [ ip-address [ vpn vpn-instance-name ] ] [ interface
interface-type interface-number | local ] [ slot slot-number ] [ count ]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
ack-flood: Specifies ACK flood attack.
dns-flood: Specifies DNS flood attack.
fin-flood: Specifies FIN flood attack.
flood: Specifies all IPv4 flood attacks.
http-flood: Specifies HTTP flood attack.
icmp-flood: Specifies ICMP flood attack.
rst-flood: Specifies RST flood attack.
syn-ack-flood: Specifies SYN-ACK flood attack.
syn-flood: Specifies SYN flood attack.
udp-flood: Specifies UDP flood attack.
ip-address: Specifies an IPv4 address. If no IPv4 address is specified, this command displays flood attack
detection and prevention statistics for all IPv4 addresses.
vpn-instance vpn-instance-name: Specifies the MPLS L3VPN instance to which the protected IPv4
address belongs. The vpn-instance-name argument is a case-sensitive string of 1 to 31 characters. Do not
specify this option if the protected IPv4 address is on the public network.
interface interface-type interface-number: Specifies an interface by its type and number.
local: Specifies the device.
slot slot-number: Specifies a card by its slot number. This option is available only when you specify a
global interface, such as a VLAN interface or tunnel interface. If no card is specified, this command
displays IPv4 flood attack detection and prevention statistics on all cards. (MSR4000.)
count: Displays the number of matching protected IPv4 addresses.
Usage guidelines
The device collects statistics about protected IP addresses for flood attack detection and prevention. The
attackers' IP addresses are not recorded.
If the interface and local parameters are not specified, this command display IPv4 flood attack detection
and prevention statistics on all interfaces and the device.
Examples
# (MSR1000/MSR2000/MSR3000.) Display flood attack detection and prevention statistics for all IPv4
addresses.
<Sysname> display attack-defense flood statistics ip