EasyManua.ls Logo

Zte ZXR10 8900 Series - Page 92

Zte ZXR10 8900 Series
177 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
ZXR108900SeriesCommandManual(FWVolume)
Parameter
Description
Parameter
Description
addThisaddsonehostorsubnettobeprotected.
protect_name
Thissetsaddressresourcetobeprotected,
whichcanbehost,subnetoraddressrange.
Thisaddressresourceshallbeaddedin
commanddefineinadvance.
<string>
Thisisonestring,indicatingthenameof
addressresource.
icmpflood
Thissetsthemaxreplyrequestsinitiatedto
protectedobjectpersecond.
<number1>Thisisonenumber,indicatingmaxconnection
requests,500bydefault,rangingfrom1to
-65535.
ipsweep
ThissetsthemaxICMPpacketssentfrom
thesameoneIPtomultiplehostswithin
thespecifiedinterval.Whenpacketnumber
reachesthisthreshold,itbelievesthat
addressesarescannedforonetime.
<number2>
Thisisonenumber,inrangeof1-65535.
synflood
Thissetsthemaxconnectionrequests
initiatedtoprotectedobjectpersecond.
<number3>
Thisisonenumber,500bydefault,ranging
from1to-65535.
udpflood
ThissetsthemaxUDPpacketssentto
protectedobjectpersecond.Whenthepacket
numberreachesthisthreshold,UDPflooding
attackprotectionfunctionisenabled.
<number4>
Thisisonenumber,1000bydefault,ranging
from1to-65535.
portscan
ThissetsthemaxIPpacketscontainingTCP
SYNsegmentsentfromthesameonesource
IPtomultipleportsofdestinationIPwithin
thespecifiedinterval.Whenpacketnumber
reachesthisthreshold,itbelievesthatports
arescannedforonetime.
<number5>
Thisisonenumber,inrangeof1-65535.
logWhenattackeventoccurs,itsetswhetherto
recorditintolog.
yes|noyes:Recordtheeventintolog;no:Don’t
recordtheeventintolog.
action
Itsetswhethertopermitpacketstopass
through.
pass|blockpass:Itindicatespermittingpacketstopass
through;block:Itindicatesdenyingpackets
passingthrough.
ExampleT oaddoneintrusiondetectionrule,setaddressofprotectedhost
tohostA,denypacketspassingthroughandrecorditinlog,exe-
cutethefollowingcommand:
#dosruleaddprotect_namehostAicmpflood800ipsweep
8synflood300udpflood300portscan8logyesaction
block
76ConfidentialandProprietaryInformationofZTECORPORATION

Table of Contents

Other manuals for Zte ZXR10 8900 Series

Related product manuals