ZXA10C300CongurationManual(CLI)
ZXAN(config)#linetelnetaccess-class10
–EndofSteps–
15.5ConguringControlPanelSafety
Afteryoucongurecontrolpanelsafety,theZXA10C300canlimittheprotocolpacketrate
andpreventDoSpacketattacks.
Context
Controlpanelsafetyincludesthefollowingthreefunctions:
lRatelimitofprotocolpackets
Differentratelimitsaresetforpacketsofdifferentprotocols.
lRatelimitofCPUqueuepackets
Packetratelimitsforeightqueuesoftheexchangechipcanbesetseparately.When
thepacketrateofacertainqueueistoohigh,acorrespondingratelimitcanbesetto
reducetheimpactontheCPU.
lBlacklist
WhenthenumberofpacketssenttotheCPUbyauserinonepollingperiod(5sby
default)exceedsthethreshold,theZXA10C300considersthattheuserimplements
aDoSattackontheNEandincludestheuserintotheblacklist.Thenpacketssent
bytheuserwillbedroppedtilltheuserstopstheattack.
Steps
1.Entercontrolpanelmode,andcongurepacketlimit.
ZXAN(config)#control-panel
ZXAN(control-panel)#packet-limitdhcp20
ZXAN(control-panel)#packet-limitarp50
2.ConguretheratelimitofCPUqueuepackets.
ZXAN(control-panel)#cpuqueue125
3.Enableanti-DoS.
ZXAN(control-panel)#anti-dosenable
4.Enabletheanti-DoSdropfunction.
ZXAN(control-panel)#anti-dosdropenable
5.Congurethethresholdoftheblacklist.
ZXAN(control-panel)#anti-doslimit-number20
6.Congurethepollingtimeoftheblacklist.
ZXAN(control-panel)#anti-dosblocking-time10
7.(Optional)Querytheblacklist.
15-6
SJ-20130520164529-007|2013-06-30(R1.0)ZTEProprietaryandCondential