attack-source-trace enable

Function

The attack-source-trace enable command enables attack source tracing.

The undo attack-source-trace enable command disables attack source tracing.

By default, attack source tracing is enabled.

Format

attack-source-trace tcpip-defend enable

attack-source-trace car enable

attack-source-trace ma-defend enable

attack-source-trace application-apperceive enable

attack-source-trace totalcar enable

attack-source-trace enable

undo attack-source-trace tcpip-defend enable

undo attack-source-trace car enable

undo attack-source-trace ma-defend enable

undo attack-source-trace application-apperceive enable

undo attack-source-trace totalcar enable

undo attack-source-trace enable

Parameters

Parameter Description Value
car

Records the packets dropped by Committed Access Rate (CAR).

-

ma-defend

Records the packets dropped by management/control plane protection.

-

application-apperceive

Records the packets dropped by application layer association.

-

totalcar

Records information about packets that are dropped when the overall rate at which packets are sent to the CPU exceeds the configured threshold.

You can run the car total-packet { high | low | middle | total-packet-rate } command to set the overall rate at which packets are sent to the CPU.

-

tcpip-defend

Records the packets dropped by defense against TCP/IP packet attacks.

-

urpf

Unicast path reverse check.

-

Views

Attack defense policy view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
cpu-defend write

Usage Guidelines

Usage Scenario

If you intend to make attack source tracing functions take effect, the attack-source-trace enable command must be enabled. (By default, this command is enabled.)

In VS mode, this command is supported only by the admin VS.

Example

# Disable attack source tracing on the interface board in slot 1.
<HUAWEI> system-view
[~HUAWEI] cpu-defend policy 8
[*HUAWEI-cpu-defend-policy-8] undo attack-source-trace enable
[*HUAWEI-cpu-defend-policy-8] quit
[*HUAWEI] slot 1
[*HUAWEI-slot-1] cpu-defend-policy 8
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >