SlideShare a Scribd company logo
Example for Configuring Local Attack Defense
Applicability
This example applies to all versions and routers.
Networking Requirements
As shown in Figure 1, users on different LANs access the Internet through Router A. To locate
attacks on Router A, attack source tracing needs to be configured to trace the attack source. The
following situations occur:
• A user on network segment Net1 frequently initiates attacks to Router A.
• The attacker sends a large number of ARP Request packets, degrading CPU
performance.
• The administrator needs to upload files to Router A using FTP. However, no FTP
connection has been set up between the administrator's host and Router A.
• Most LAN users obtain IP addresses through DHCP, whereas Router A does not first
process DHCP client packets sent to the CPU.
Configurations should be performed on Router A to solve the preceding problems.
NOTE:
This section provides only the configuration procedures related to local attack defense.
For details about routing configurations, see the Configuration Guide - IP Routing.
1
Figure 1 Networking diagram of attack defense policy configurations
Procedure
1. Configure the router.
#
acl number 4001 //Configure the ACL to be referenced by the blacklist of local attack
defense.
rule 5 permit source-mac 0001-c0a8-0102
#
cpu-defend policy devicesafety //Create a local attack defense policy.
auto-defend enable //Enable the attack source tracing capability.
auto-defend threshold 50 //Set the attack source tracing threshold to 50 pps.
blacklist 1 acl 4001 //Specify the blacklist.
packet-type arp-request rate-limit 64 //Set the rate limit for ARP request packets sent to
the CPU to 64 pps.
application-apperceive packet-type ftp rate-limit 2000 //Set the rate limit for FTP packets
to 2000 pps.
packet-type dhcp-client priority 3 //Set the priority of the DHCP-client packets sent to the
CPU to 3.
#
cpu-defend-policy devicesafety //Apply the attack defense policy to the MPU.
#
return
2. Verify the configuration.
2
Run the display cpu-defend policy command on router A to view information about the
attack defense policy.
Run the display cpu-defend configuration command on router A to view rate limit on
protocol packets.
More related:
Example for Configuring the SNMP Function to Implement Communication Between the Device and the NMS
Example for Connecting Intranet Users to the Internet in Easy IP Mode
Example for Configuring the Device as a PPPoE Client to Connect Users to the Internet
How to Configure the PPPoE Client on Huawei AR1200?
Example for Connecting Intranet Users to the Internet in NAT Address Pool Mode
More Huawei products and Reviews you can visit: http://www.huanetwork.com/blog
Huanetwork.com is a world leading Huawei networking products distributor, we wholesale original new Huawei
networking equipments, including Huawei switches, Huawei routers, Huaweisymantec security products, Huawei IAD,
Huawei SFP and other Huawei networking products. Our customers include telecom operators, Huawei resellers, ISP and
system integrators. Right now most of our sales are contributed by regular customers.
In Huanetwork Lab, also we have Huawei OLT, MDU, DSLAM and switch for customer do remote testing, any potential
customer are welcome to login to our lab. If you need a total Huawei FTTx solution or Huawei ADSL solution for your
network, also you may feel free to contact us.
Our website: http://www.huanetwork.com
Telephone: +852-30501940
Email: sales@huanetwork.com
Address: 23/F Lucky Plaza, 315-321 Lockhart Road, Wanchai, Hongkong
3

More Related Content

PDF
GLBP (gateway load balancing protocol)
PPTX
BASICS OF ROUTING IN NETWORKS
PDF
VLAN Trunking Protocol
PDF
200 301-ccna
PDF
VRRP (virtual router redundancy protocol)
PPTX
PPTX
Ccna ppt1
GLBP (gateway load balancing protocol)
BASICS OF ROUTING IN NETWORKS
VLAN Trunking Protocol
200 301-ccna
VRRP (virtual router redundancy protocol)
Ccna ppt1

What's hot (20)

PDF
MPLS Concepts and Fundamentals
PDF
Cisco Digital Network Architecture - Introducing the Network Intuitive
PPT
firewall.ppt
PPTX
IMS presentation
PPTX
Bgp protocol
PPT
Mpls L3_vpn
PPT
PDF
VLAN (virtual local area network)
PPT
PDF
CCNAv5 - S2: Chapter5 Inter Vlan Routing
PDF
cours ospf
PPTX
IS-IS Packet Types
PPT
PPTX
Routing Techniques
PPTX
Routing Protocols
PDF
Router commands
PPTX
Network Troubleshooting - Part 2
DOCX
Layer 2 & layer 3 switching
PPTX
CCNA Course Training Presentation
PPT
IP Subnetting
MPLS Concepts and Fundamentals
Cisco Digital Network Architecture - Introducing the Network Intuitive
firewall.ppt
IMS presentation
Bgp protocol
Mpls L3_vpn
VLAN (virtual local area network)
CCNAv5 - S2: Chapter5 Inter Vlan Routing
cours ospf
IS-IS Packet Types
Routing Techniques
Routing Protocols
Router commands
Network Troubleshooting - Part 2
Layer 2 & layer 3 switching
CCNA Course Training Presentation
IP Subnetting
Ad

Viewers also liked (9)

DOC
Version support for huawei s7700 components (1)
DOC
Huawei s9300 terabit routing switch
DOC
Optical module
DOC
Huawei S5700 28 p-pwr-li-ac introduction
DOC
Huawei s3700 cables
DOC
Huawei net engine5000e core router chassis and features
DOC
What is huawei quidway s5300 gigabit switches
DOC
Huawei osn3500 typical networking in packet mode
DOC
Huawei s2300 series ethernet switches overview
Version support for huawei s7700 components (1)
Huawei s9300 terabit routing switch
Optical module
Huawei S5700 28 p-pwr-li-ac introduction
Huawei s3700 cables
Huawei net engine5000e core router chassis and features
What is huawei quidway s5300 gigabit switches
Huawei osn3500 typical networking in packet mode
Huawei s2300 series ethernet switches overview
Ad

Similar to Example for configuring local attack defense (20)

PDF
versa router teletronics
PDF
Ccnav5.org ccna 4-v50_practice_final_exam
DOCX
2232016 Sample Implementation Plan1.htmlfileCUsers.docx
DOC
Configuring the Device as a PPPoE Client on Huawei AR1200
PPT
Vpnppt1884
PDF
CCNA 1 Chapter 11 v5.0 2014
DOCX
Telnet configuration
PDF
Ccna 4 Final 2 Version 4.0 Answers
PDF
IT Essentials (Version 7.0) - ITE Chapter 5 Exam Answers
PDF
Guide to Firewalls and VPNs 3rd Edition Whitman Test Bank
PPTX
introduction of iptables in linux
PPTX
Case study
PPT
Linux Based Advanced Routing with Firewall and Traffic Control
PDF
PPT
Tonyfortunatoiperfquickstart 1212633021928769-8
PDF
Www ccnav5 net_ccna_3_v5_final_exam_answers_2014
PPTX
cFrame framework slides
PDF
200-301-demo.pdf
PDF
Cisco 200-301 Exam Dumps
PDF
Cisco 200-301 Exam Dumps
versa router teletronics
Ccnav5.org ccna 4-v50_practice_final_exam
2232016 Sample Implementation Plan1.htmlfileCUsers.docx
Configuring the Device as a PPPoE Client on Huawei AR1200
Vpnppt1884
CCNA 1 Chapter 11 v5.0 2014
Telnet configuration
Ccna 4 Final 2 Version 4.0 Answers
IT Essentials (Version 7.0) - ITE Chapter 5 Exam Answers
Guide to Firewalls and VPNs 3rd Edition Whitman Test Bank
introduction of iptables in linux
Case study
Linux Based Advanced Routing with Firewall and Traffic Control
Tonyfortunatoiperfquickstart 1212633021928769-8
Www ccnav5 net_ccna_3_v5_final_exam_answers_2014
cFrame framework slides
200-301-demo.pdf
Cisco 200-301 Exam Dumps
Cisco 200-301 Exam Dumps

More from Huanetwork (20)

PDF
Huawei s5710-ei-power-module-test-report
DOC
Huanetwork x dsl solution - huawei adsl2+ and vdsl2 solution)
DOC
Wiki and solution in ftth technology
DOC
Ont, olt and mdu in gpon technology
DOC
What are the differences between huawei and cisco wlan products
DOC
Huawei ac6005
DOC
How to Configure QinQ?
DOC
How to configure inband management for huawei ma5616
DOC
How to configure eo c services for huawei ol ts
DOC
Huawei opti x osn 1500 boards
DOC
Huawei ftth c b e2 e solution
DOC
Huawei osn3500 typical networking in packet mode
DOC
What’s the Difference Between GPON and EPON
DOC
Differences of Huawei S5700 Series LI, SI, EI and HI
DOC
How to configure the logical distance of gpon
DOC
Huanetwork Design the Network Solution Free for You
DOC
Configuration difference between ipv6 and ipv4
DOC
How to configure the gpon ftth layer 2 internet access service on the nms
DOC
How to configure i pv6 services in the fttb c (no hgws) scenario
DOC
Huawei router component selection guide – purchase list
Huawei s5710-ei-power-module-test-report
Huanetwork x dsl solution - huawei adsl2+ and vdsl2 solution)
Wiki and solution in ftth technology
Ont, olt and mdu in gpon technology
What are the differences between huawei and cisco wlan products
Huawei ac6005
How to Configure QinQ?
How to configure inband management for huawei ma5616
How to configure eo c services for huawei ol ts
Huawei opti x osn 1500 boards
Huawei ftth c b e2 e solution
Huawei osn3500 typical networking in packet mode
What’s the Difference Between GPON and EPON
Differences of Huawei S5700 Series LI, SI, EI and HI
How to configure the logical distance of gpon
Huanetwork Design the Network Solution Free for You
Configuration difference between ipv6 and ipv4
How to configure the gpon ftth layer 2 internet access service on the nms
How to configure i pv6 services in the fttb c (no hgws) scenario
Huawei router component selection guide – purchase list

Recently uploaded (20)

PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Approach and Philosophy of On baking technology
PPTX
Big Data Technologies - Introduction.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPT
Teaching material agriculture food technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
cuic standard and advanced reporting.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
Review of recent advances in non-invasive hemoglobin estimation
Approach and Philosophy of On baking technology
Big Data Technologies - Introduction.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
Teaching material agriculture food technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Spectral efficient network and resource selection model in 5G networks
20250228 LYD VKU AI Blended-Learning.pptx
Machine learning based COVID-19 study performance prediction
cuic standard and advanced reporting.pdf
Electronic commerce courselecture one. Pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
MIND Revenue Release Quarter 2 2025 Press Release
Agricultural_Statistics_at_a_Glance_2022_0.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Network Security Unit 5.pdf for BCA BBA.
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Mobile App Security Testing_ A Comprehensive Guide.pdf

Example for configuring local attack defense

  • 1. Example for Configuring Local Attack Defense Applicability This example applies to all versions and routers. Networking Requirements As shown in Figure 1, users on different LANs access the Internet through Router A. To locate attacks on Router A, attack source tracing needs to be configured to trace the attack source. The following situations occur: • A user on network segment Net1 frequently initiates attacks to Router A. • The attacker sends a large number of ARP Request packets, degrading CPU performance. • The administrator needs to upload files to Router A using FTP. However, no FTP connection has been set up between the administrator's host and Router A. • Most LAN users obtain IP addresses through DHCP, whereas Router A does not first process DHCP client packets sent to the CPU. Configurations should be performed on Router A to solve the preceding problems. NOTE: This section provides only the configuration procedures related to local attack defense. For details about routing configurations, see the Configuration Guide - IP Routing. 1
  • 2. Figure 1 Networking diagram of attack defense policy configurations Procedure 1. Configure the router. # acl number 4001 //Configure the ACL to be referenced by the blacklist of local attack defense. rule 5 permit source-mac 0001-c0a8-0102 # cpu-defend policy devicesafety //Create a local attack defense policy. auto-defend enable //Enable the attack source tracing capability. auto-defend threshold 50 //Set the attack source tracing threshold to 50 pps. blacklist 1 acl 4001 //Specify the blacklist. packet-type arp-request rate-limit 64 //Set the rate limit for ARP request packets sent to the CPU to 64 pps. application-apperceive packet-type ftp rate-limit 2000 //Set the rate limit for FTP packets to 2000 pps. packet-type dhcp-client priority 3 //Set the priority of the DHCP-client packets sent to the CPU to 3. # cpu-defend-policy devicesafety //Apply the attack defense policy to the MPU. # return 2. Verify the configuration. 2
  • 3. Run the display cpu-defend policy command on router A to view information about the attack defense policy. Run the display cpu-defend configuration command on router A to view rate limit on protocol packets. More related: Example for Configuring the SNMP Function to Implement Communication Between the Device and the NMS Example for Connecting Intranet Users to the Internet in Easy IP Mode Example for Configuring the Device as a PPPoE Client to Connect Users to the Internet How to Configure the PPPoE Client on Huawei AR1200? Example for Connecting Intranet Users to the Internet in NAT Address Pool Mode More Huawei products and Reviews you can visit: http://www.huanetwork.com/blog Huanetwork.com is a world leading Huawei networking products distributor, we wholesale original new Huawei networking equipments, including Huawei switches, Huawei routers, Huaweisymantec security products, Huawei IAD, Huawei SFP and other Huawei networking products. Our customers include telecom operators, Huawei resellers, ISP and system integrators. Right now most of our sales are contributed by regular customers. In Huanetwork Lab, also we have Huawei OLT, MDU, DSLAM and switch for customer do remote testing, any potential customer are welcome to login to our lab. If you need a total Huawei FTTx solution or Huawei ADSL solution for your network, also you may feel free to contact us. Our website: http://www.huanetwork.com Telephone: +852-30501940 Email: sales@huanetwork.com Address: 23/F Lucky Plaza, 315-321 Lockhart Road, Wanchai, Hongkong 3