ipv6-abnormal-packet-defend enable

Function

The ipv6-abnormal-packet-defend enable command enables defense against malformed IPv6 packet attacks.

The undo ipv6-abnormal-packet-defend enable command disables defense against malformed IPv6 packet attacks.

By default, defense against malformed IPv6 packet attacks is enabled.

Format

ipv6-abnormal-packet-defend enable

undo ipv6-abnormal-packet-defend enable

Parameters

None

Views

Attack defense policy view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
device-mgr write

Usage Guidelines

Usage Scenario

When defense against malformed IPv6 packet attacks is enabled, the interface board checks the received malformed IPv6 packets (LAND attack packets, and TCP tag bit invalid attack packets). Send the packets that pass check. Discard the packets that fail check.

In VS mode, this command is supported only by the admin VS.

Example

# Enable defense against malformed IPv6 packet attacks of attack defense policy 7.
<HUAWEI> system-view
[~HUAWEI] cpu-defend policy 7
[*HUAWEI-cpu-defend-policy-7] ipv6-abnormal-packet-defend enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >