EasyManua.ls Logo

HP MSR SERIES

HP MSR SERIES
684 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
627
icmp-flood action
Use icmp-flood action to specify global actions against ICMP flood attacks.
Use undo icmp-flood action to restore the default.
Syntax
icmp-flood action { drop | logging } *
undo icmp-flood action
Default
No action is taken against detected ICMP flood attacks.
Views
Attack defense policy view
Predefined user roles
network-admin
Parameters
drop: Drops subsequent ICMP packets destined for the victim IP addresses.
logging: Enables logging for ICMP flood attack events. The log information records the detection
interface, victim IP address, MPLS L3VPN instance name, current packet statistics, prevention actions,
and start time of the attack.
Examples
# Specify drop as the global action against ICMP flood attacks in attack defense policy atk-policy-1.
<Sysname> system-view
[Sysname] attack-defense policy atk-policy-1
[Sysname-attack-defense-policy-atk-policy-1] icmp-flood action drop
Related commands
• icmp-flood detect non-specific
• icmp-flood detect ip
• icmp-flood threshold
icmp-flood detect ip
Use icmp-flood detect ip to configure IP-specific ICMP flood attack detection.
Use undo icmp-flood detect ip to remove the ICMP flood attack detection configuration for an IP address.
Syntax
icmp-flood detect ip ip-address [ vpn-instance vpn-instance-name ] [ threshold threshold-value ] [ action
{ drop | logging } * ]
undo icmp-flood detect ip ip-address [ vpn-instance vpn-instance-name ]
Default
ICMP flood attack detection is not configured for any IP address.

Table of Contents

Other manuals for HP MSR SERIES

Related product manuals