HP Comware 5 Debug Manual Vol 1

Table 52 Output from the debugging attack-defense event command
Field
Description
Attack begin.
Attack type: type
Interface: interface-type interface-number
Action: action
IP address: ip-address
Attack end.
Information about the detected attack:
Attack typeThe attack type, Scan, UDP Flood, ICMP Flood, or
SYN Flood.
InterfaceInterface where attack protection is configured.
ActionAction against the attack. Available action parameters
are:
noneTakes no actions but outputs the attack alarm logs.
drop packetAlso drops attack packets.
send RST to destination hostAlso sends an RST message to
the destination host.
drop packet and add source host to blacklistAlso drops
attack packets and adds the attacker's IP address to the
blacklist.
IP addressAttacker's IP address for scanning attacks or the
victim IP address for flood attacks.
Single packet attack.
Attack type: type
Interface: interface-type interface-number
Action: action
Source IP address: src-ip-address
Destination IP address: dest-ip-address
Information about the detected single packet attack.
Attack typeTypes include Land, Smurf, Fraggle, Winnuke,
ICMP Redirect, ICMP Unreachable, Tracert, TCP Flag, Large
ICMP, Source Route, and Route Record.
InterfaceInterface that receives the attack packets.
ActionAction against the attack. Available action parameters
are:
noneTakes no additional actions but outputs the attack
alarm logs.
drop packetAlso drops the attack packets.
Source IP addressIP address of the attack source.
Destination IP addressVictim IP address.
Success to add ip-address to blacklist,
aging time is aging-time(s).
Attack added ip-address to the blacklist, and the aging time is
aging-time(s).
Table 53 describes output fields and messages for the debugging attack-defense error command.
Table 53 Output from the debugging attack-defense error command
Field
Description
Failed to add ip-address to blacklist for
already existing.
The attack protection module failed to add ip-address to the
blacklist for the entry already exists.
Failed to add ip-address to blacklist.
The attack protection module failed to add ip-address to the
blacklist due to insufficient hardware or software resources.
Failed to send attack-type log to IC.
The attack protection module failed to send the attack alarm logs to
the information center (IC) after detecting an attack.
The attack types include Land, Smurf, Fraggle, Winnuke, ICMP
Redirect, ICMP Unreachable, Tracert, TCP Flag, Large ICMP,
Source Route, Route Record, Scan, UDP Flood, ICMP Flood, and
SYN Flood.
113