display ma-defend interface-policy

Function

The display ma-defend interface-policy command displays information about interface-based policy for management and service plane protection.

Format

display ma-defend interface-policy interface-policy-id

Parameters

Parameter Description Value
interface-policy-id

Specifies the ID of a configured interface-based policy for management and service plane protection.

The value is an integer ranging from 1 to 64.

Views

All views

Default Level

1: Monitoring level

Task Name and Operations

Task Name Operations
hostdefend read

Usage Guidelines

Usage Scenario

To help the device defend against attacks or unauthorized logins initiated by sending protocol packets, management and service plane protection is used to prevent packets of a specified protocol or all protocols from being sent to the CPU. Using management and service plane protection improves device security and reliability and ensures normal network operation.

To verify management and service plane protection or troubleshoot faults, run the display ma-defend interface-policy command to view information about interface-based policy.

Precautions

In VS mode, this command is supported only by the admin VS.

Example

The actual command output varies according to the device. The command output here is only an example.

# Displays information about interface-based policy for management and service plane protection.
<HUAWEI> display ma-defend interface-policy 1
MA-defend policy type: interface-policy
----------------------------------------------------
  The interface-policy is enabled
  --------------------------------------------------
  protocol       rule
  --------------------------------------------------
  FTP            deny
  BGP            permit
----------------------------------------------------
Table 1 Description of the display ma-defend interface-policy command output
Item Description
MA-defend policy type

Type of policy for management and service plane protection:

  • all: all policies.
  • global-policy: policy taking effect on the Router.
  • interface-policy: policy taking effect on an interface.
  • slot-policy: policy taking effect on a board.
protocol

Protocol name, which was defined in the protocol command.

rule

Rule defined in a policy:

  • deny: drops packets.
  • permit: allows packets to be sent to the CPU.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >