< Home

Which Packets Cannot Be Filtered by the ACL Used by a Traffic Policy?

The ACL used by a traffic policy cannot filter the protocol packets to be sent to the CPU.

To filter the protocol packets to be sent to the CPU, you can apply an ACL to the blacklist configured in the local attack defense policy. The configuration procedure is as follows:

  1. Run the cpu-defend policy policy-name command in the system view to create an attack defense policy.

  2. Run the blacklist blacklist-id acl acl-number command to create a blacklist.

  3. Run the cpu-defend-policy policy-name [ global ] command in the system view or run the cpu-defend-policy policy-name command in the slot view to apply the attack defense policy.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >