< Home

anti-attack abnormal enable

Function

The anti-attack abnormal enable command enables defense against malformed packet attacks.

The undo anti-attack abnormal enable command disables defense against malformed packet attacks.

The anti-attack abnormal disable command disables defense against malformed packet attacks.

By default, defense against malformed packet attacks is enabled.

Format

anti-attack abnormal enable

undo anti-attack abnormal enable

anti-attack abnormal disable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

The malformed packet attack is to send malformed IP packets to the system. If such an attack occurs, the system may break down when processing the malformed IP packets. To prevent the system from breaking down and to ensure normal network services, run the anti-attack abnormal enable command to enable defense against malformed packets.

The device detects malformed packets after defense against malformed packets is enabled.

The device directly discards packets of the following types:

  • Flood attacks from IP null payload packets

  • Attacks from IGMP null payload packets

  • LAND attacks

  • Smurf attacks

  • Attacks from packets with invalid TCP flag bits

Precautions

You can also run the anti-attack enable command in the system view to enable attack defense against all attack packets including malformed packets.

Example

# Enable defense against malformed packet attacks.

<HUAWEI> system-view
[HUAWEI] anti-attack abnormal enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >