How to configure Anti-Attack
Enabling anti-DoS attack and anti-ICMP/IP attack, and configuring the source route filtering and source MAC address filtering functions can prevent malicious users' attack on the system, so as to improve system security.
The Huawei MA5600 supports the following measures to prevent malicious users' attack on the system. Choose measures according to actual requirements.
Anti-DoS attack: Indicates the defensive measures taken by the system to receive only a certain number of control packets sent from a user.
Anti-ICMP attack: Indicates the defensive measures taken by the system to drop the ICMP packets sent from the user-side device to the MA5600. This is to prevent the user-side device from pinging the VLAN interface of the Huawei MA5600.
Anti-IP attack: Indicates the defensive measures taken by the system to drop the IP packets sent from the user-side device to the MA5600.
Source route filtering: Indicates the defensive measures taken by the system to filter the IP packets that are sent by the user and carry the routing option field.
Source MAC address filtering: Indicates the defensive measures taken by the system to filter the packets that are sent by the user and carry certain source MAC addresses.
User-side ring network check: Indicates the defensive measures taken by the system to check user-side ring networks. In this manner, the system can process ring networks to prevent ring networks from affecting services.
Configure anti-DoS attack.
Configure anti-ICMP attack.
Enable the source route filtering function.
Configure the MAC address filtering function.
Run the security anti-dos enable command to enable anti-DoS attack. After the anti-DoS attack function is enabled, the system adds the user port to the blacklist if the receive rate of the control packet of the user reaches a preset value. When anti-DoS attack is disabled, the system deletes the blacklist.
Application scenario: Two PCs (PC1 and PC2) are connected to the network through the MA5600. If a malicious user (PC1) sends a large number of protocol control packets to attack the CPU of the MA5600, the CPU usage of the MA5600 will be over high, and then the MA5600 is unable to process the services of another user (PC2). To implement anti-DoS attack, shield the attack port to protect the MA5600 from being attacked.
Run the security anti-icmpattack enable command to enable anti-ICMP attack. Anti-ICMP attack is used to prevent the user-side device from pinging the VLAN interface of the Huawei MA5600.
Application scenario: Two PCs (PC1 and PC2) are connected to the network through the MA5600. When PC2 sends a large number of ICMP packets to the VLAN interface, the services of the user (PC1) that obtains the upper-layer DHCP information through the same VLAN interface will be abnormal. To implement anti-ICMP attack, directly drop the user-side ICMP packets if the IP address of the VLAN interface on the MA5600 is its destination IP address.
Run the security anti-ipattack enable command to enable anti-IP attack. The anti-IP attack is used to prevent user-side IP packets from attacking the L3 interface of the device or to prevent illegal users from logging in to the device through telnet.
Application scenario: When a PC sends the packets with the address of VLAN x as the destination IP address to VLANIF x, it may send a large number of packets to attack the device, causing the device to fail to process normal services; when a user knows the address of VLAN x, or the user name and password for logging in to the device, it may log in to the device through telnet to randomly change the configurations of the device. To prevent the two preceding cases, the device needs to implement anti-IP attack. With this feature, the device drops the packets with the address of the device interface as the destination IP address to prevent the user from attacking the device.
Run the security source-route enable command to enable the source route filtering function. This function is used to filter the packets that carry the routing information and are reported to the L3 switch.
Application scenario: In general, routes are dynamic and application does not control route selection. The sender can add the routing information to IP packets through the source route to perform route selection. In this case, packets go along a specific route on the network according to the intention of the sender. To prevent the preceding cases, enable the source route filtering function. Then the MA5600 performs validity check on IP packets and drops the packets that match the source route options.
Run the security mac-filter command to enable the MAC address filtering function.
Application scenario: To prevent users from forging the MAC address of the network-side device, or forging certain renowned MAC addresses, set the MAC address of the network-side as the MAC address to be filtered.
Website: http://www.thunder-link.com/
How to Configuring an xDSL Port
How to configure the VoD Service
How to configure Link Aggregation and Security Policy