华为 SecPath 防火墙 常见flood攻击防范典型配置

一、 组网需求

SecPath 开启syn-flood、icmp-flood和udp-flood的攻击 防范,防止对Server的flood攻击

二、组网图

 

 

 

 

    软件版本如下:

    SecPath10F VRP 3.40 ESS 1604

三、配置 步骤

[Quidway]dis cur                                                                  

#                                                                              

  sysname Quidway                                                                 

#                                                                              

  firewall packet-filter enable                                                 

  firewall packet-filter default permit                                         

#                                                                               

  undo connection-limit enable                                                  

  connection-limit default deny                                                 

  connection-limit default amount upper-limit 50 lower-limit 20                 

#                                                                              

  firewall statistic system enable            //开启报文全局统计                    

#                                                                               

radius scheme system                                                           

#                                                                              

domain system                                                                   

#                                                                              

local-user admin                                                               

  password cipher .]@USE=B,53Q=^Q`MAF4<1!!                                       

  service-type telnet terminal                                                  

  level 3                                                                       

  service-type ftp                                                               

#                                                                              

acl number 3000                                                                

  rule 1 permit ip source 192.168.1.0 0.0.0.255                                 

#                                                                               

interface Ethernet1/0                                                          

  ip address 10.0.0.254 255.255.0.0                                             

#                                                                               

interface Ethernet2/0                                                          

  speed 10                                                                      

  duplex full                                                                   

  ip address 192.168.1.254 255.255.255.0                                        

#                                                                              

interface NULL0                                                                

#                                                                              

firewall zone local                                                            

  set priority 100                                                               

#                                                                              

firewall zone trust                                                            

  add interface Ethernet2/0                                            

  set priority 85                                                               

#                                                                              

firewall zone untrust                                                           

  add interface Ethernet1/0                  //服务器加入非信任域                                 

  set priority 5                                                                

  statistic enable ip inzone                 //开启所在域入方向的报文统计                                 

#                                                                              

firewall zone DMZ                                                              

  set priority 50                                                                

#                                                                              

firewall interzone local trust                                                 

#                                                                              

firewall interzone local untrust                                               

#                                                                              

firewall interzone local DMZ                                                   

#                                                                               

firewall interzone trust untrust                                               

#                                                                              

firewall interzone trust DMZ                                                   

#                                                                              

firewall interzone DMZ untrust                                                 

#                                                                               

  FTP server enable                                                             

#                                                                              

  firewall defend land                                                           

  firewall defend smurf                                                         

  firewall defend winnuke                                                       

  firewall defend syn-flood enable            //使能syn-flood攻击范                            

  firewall defend icmp-flood enable         //使能imcp-flood攻击防范                  

                                           //设置受保护主机和启用tcp代理

firewall defend syn-flood ip 10.0.0.1 max-rate 100 tcp-proxy                  

  firewall defend icmp-flood ip 10.0.0.1     //设置受保护的主机                           

#                                                                              

user-interface con 0                                                           

user-interface vty 0 4                                                          

  authentication-mode scheme                                                    

#                                                                              

return                                                                          

 

                                  

                                                                           

四、 配 置关键点

1. 在全局下开启报文统 计;

2. 开启受保护主机所在域 的入方向的报文统计;

3. 使能相应的 flood 攻击防范;

4. 设置受保护主机。

五、 验 证结果

在攻击机 Attacker 192.168.1.1 上对 10.0.0.1 进行 syn-flood icmp-flood 攻击,防火墙 告警。

[Quidway]                                                                         

%Jan1 08:01:06:125 2000 Quidway SEC/5/ATCKDF:atckType(1016)=(6)ICMP-flood;rcvIfNa

me(1023)=Ethernet2/0;srcIPAddr(1017)=192.168.1.1;srcMacAddr(1021)=;destIPAddr(1019)=10.0.0.1;destMacAddr(1022)=;atckSpeed(1047)=1000;atckTime_cn(1048)=20000101080102                                                                          

[Quidway]                                                                         

%Jan1 08:01:36:125 2000 Quidway SEC/5/ATCKDF:atckType(1016)=(5)SYN-flood;rcvIfNam

e(1023)=Ethernet2/0;srcIPAddr(1017)=192.168.1.1;srcMacAddr(1021)=;destIPAddr(1019)=10.0.0.1;destMacAddr(1022)=;atckSpeed(1047)=100;atckTime_cn(1048)=20000101080117    

 

无忧网客联盟专业讨论网络技术,CCNA CCNP CCIE CCSP

文章转载至http://bbs.net527.cn   无忧网客联盟

无忧linux时代

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值