R3303-HP HSR6800 Routers Security Command Reference

438
Related commands
display attack-defense policy
blacklist enable
Use blacklist enable to enable the blacklist function.
Use undo blacklist enable to restore the default.
Syntax
blacklist enable
undo blacklist enable
Default
The blacklist function is disabled.
Views
System view
Default command level
2: System level
Usage guidelines
After the blacklist function is enabled, you can add blacklist entries manually or configure the device to
add blacklist entries automatically. The auto-blacklist function must cooperate with the scanning attack
protection function or the user login authentication function. For configuration information about
scanning attack protection, see the defense scan add-to-blacklist command.
Examples
# Enable the blacklist function.
<Sysname> system-view
[Sysname] blacklist enable
Related commands
defense scan
display attack-defense policy
blacklist ip
Use blacklist ip to add a blacklist entry. After an IP address is added to the blacklist, the device filters all
packets from it.
Use undo blacklist to delete blacklist entries or cancel the aging time configuration of a blacklist entry.
Syntax
blacklist ip source-ip-address [ timeout minutes ]
undo blacklist { all | ip source-ip-address [ timeout ] }
Views
System view