R0106-HP MSR Router Series Security Command Reference(V7)

582
Examples
# (MSR2000/MSR3000.) Display information about all IPv6 addresses protected by flood attack
detection and prevention in attack defense policy abc.
<Sysname> display attack-defense policy abc flood ipv6
IPv6 address VPN instance Type Rate threshold(PPS) Dropped
2013::127f a012345678901234 SYN-ACK-FLOOD 100 4294967295
2::5 -- ACK-FLOOD 100 10
1::5 -- ACK-FLOOD 100 23
# (MSR4000.) Display information about all IPv6 addresses protected by flood attack detection and
prevention in attack defense policy abc.
<Sysname> display attack-defense policy abc flood ipv6
Slot 0:
IPv6 address VPN instance Type Rate threshold(PPS) Dropped
2013::127f a012345678901234 SYN-ACK-FLOOD 100 4294967295
2::5 -- ACK-FLOOD 100 10
1::5 -- ACK-FLOOD 100 23
Slot 1:
IPv6 address VPN instance Type Rate threshold(PPS) Dropped
2013::127f a012345678901234 SYN-ACK-FLOOD 100 4294967295
2::5 -- ACK-FLOOD 100 10
1::5 -- ACK-FLOOD 100 23
# (MSR2000/MSR3000.) Display the number of IPv6 addresses protected by flood attack detection and
prevention in attack defense policy abc.
<Sysname> display attack-defense policy abc flood ipv6 count
Totally 3 flood protected entries.
# (MSR4000.) Display the number of IPv6 addresses protected by flood attack detection and prevention
in attack defense policy abc.
<Sysname> display attack-defense policy abc flood ipv6 count
Slot 0:
Totally 3 flood protected IP addresses.
Slot 1:
Totally 3 flood protected IP addresses.
Table 86 Command output
Field Descri
p
tion
Totally 3 flood protected IP
addresses
Total number of the IPv6 addresses protected by flood attack detection and
prevention.
IPv6 address Protected IPv6 address.
VPN instance
MPLS L3VPN instance to which the protected IPv6 address belongs. If the
protected IPv6 address is on the public network, this field displays hyphens
(--).
Type Type of the flood attack.
Rate threshold(PPS)
Threshold for triggering the flood attack prevention, in units of packets sent
to the IPv6 address per second.
Dropped
Number of dropped attack packets. If the prevention action is logging, this
field displays 0.