R0106-HP MSR Router Series Security Command Reference(V7)

574
display attack-defense policy
Use display attack-defense policy to display attack defense policy configuration.
Syntax
display attack-defense policy [ policy-name ]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
policy-name: Specifies an attack defense policy by its name. The policy name is a case-insensitive string
of 1 to 31 characters. Valid characters include uppercase and lowercase letters, digits, underscores (_),
and hyphens (-). If no attack defense policy is specified, this command displays brief information about
all attack defense policies.
Usage guidelines
This command output includes the following configuration information about an attack defense policy:
Whether attack detection is enabled.
Attack prevention actions.
Attack prevention trigger thresholds.
Examples
# Display the configuration of attack defense policy abc.
<Sysname> display attack-defense policy abc
Attack-defense Policy Information
--------------------------------------------------------------------------
Policy name : abc
Applied list : GE2/1/1
Vlan1
--------------------------------------------------------------------------
Exempt IPv4 ACL: : Not configured
Exempt IPv6 ACL: : vip
--------------------------------------------------------------------------
Actions: CV-Client verify BS-Block source L-Logging D-Drop N-None
Signature attack defense configuration:
Signature name Defense Level Actions
Fragment Enabled Info L
Impossible Enabled Info L
Teardrop Disabled Info L
Tiny fragment Disabled Info L
IP option abnormal Disabled Info L
Smurf Disabled Info N
Traceroute Disabled Medium L,D