华为原配置
anti-ddos syn-flood source-detect
anti-ddos udp-flood dynamic-fingerprint-learn
| undo icmp name net-redirect receive |
| undo icmp name host-redirect receive |
| undo icmp name timestamp-request receive |
| undo icmp name timestamp-reply receive |
| undo icmp type 17 code 0 receive |
| undo icmp type 18 code 0 receive |
华为原配置
anti-ddos syn-flood source-detect
anti-ddos udp-flood dynamic-fingerprint-learn
| undo icmp name net-redirect receive |
| undo icmp name host-redirect receive |
| undo icmp name timestamp-request receive |
| undo icmp name timestamp-reply receive |
| undo icmp type 17 code 0 receive |
| undo icmp type 18 code 0 receive |
针对你提供的华为攻击防范配置,对应翻译为H3C设备(V7版本)的命令如下。
需要说明的是,华为与H3C在安全功能的设计逻辑上有很大不同。因此,下面的翻译并非严格一一对应,而是根据功能意图给出的替代实现方案。同时要特别提醒:禁用全部ICMP重定向(ICMP Redirect)报文可能导致路由收敛不准确,带来网络连通性风险,请谨慎配置。
| 华为原配置 | 功能说明 | H3C 对应命令(V7版本) | H3C 命令说明 |
|---|---|---|---|
anti-ddos syn-flood source-detect | 开启SYN Flood攻击源探测 | tcp anti-syn-flood enable | 全局开启TCP SYN Flood攻击防范功能 |
anti-ddos udp-flood dynamic-fingerprint-learn | 开启UDP Flood攻击动态指纹学习 | udp-flood detect non-specific | 对所有非受保护IP开启UDP Flood攻击检测 |
相关的H3C配置手册和详细命令可参见 H3C官方文档。
需要特别说明的是,在H3C V7系统中,并不能直接在“接收”方向上“关闭”某些特定类型的ICMP报文。因此,需要采用“先禁止设备发送、再用ACL过滤接收”两步走的方案来实现你的需求。
| 华为原配置 | 功能说明 | H3C 对应命令 (V7版本) |
|---|---|---|
undo icmp name net-redirect receive | 禁止接收网络重定向 | undo ip redirects enable |
undo icmp name host-redirect receive | 禁止接收主机重定向 | undo ip redirects enable |
undo icmp name timestamp-request receive | 禁止接收时间戳请求 | acl advanced 3000rule 5 deny icmp icmp-type timestamp-request |
undo icmp name timestamp-reply receive | 禁止接收时间戳应答 | acl advanced 3000rule 10 deny icmp icmp-type timestamp-reply |
undo icmp type 17 code 0 receive | 禁止接收类型17/码0 (地址掩码请求) | acl advanced 3000rule 15 deny icmp icmp-type 17 |
undo icmp type 18 code 0 receive | 禁止接收类型18/码0 (地址掩码应答) | acl advanced 3000rule 20 deny icmp icmp-type 18 |
注意:
undo ip redirects enable命令的功能是关闭设备的ICMP重定向报文发送功能,在H3C V7设备上,该功能默认即为关闭状态。
system-view
tcp syn-flood defense enable
udp-flood defense enable
undo ip redirects enable
undo ip redirects enable
undo icmp timestamp receive enable
undo icmp mask request receive enable
undo icmp mask reply receive enable
system-view
# SYN 泛洪防御
tcp syn-flood defense enable
# UDP 泛洪防御
udp-flood defense enable
# 关闭重定向(网络重定向 + 主机重定向)
undo ip redirects enable
# 关闭时间戳请求/应答
undo icmp timestamp receive enable
# 关闭地址掩码请求(Type17)
undo icmp mask request receive enable
# 关闭地址掩码应答(Type18)
undo icmp mask reply receive enable
| 华为命令 | 华三命令 | 功能 |
|---|---|---|
| anti-ddos syn-flood source-detect | tcp syn-flood defense enable | SYN 泛洪源检测 |
| anti-ddos udp-flood dynamic-fingerprint-learn | udp-flood defense enable | UDP 泛洪防御 |
| undo icmp name net-redirect receive | undo ip redirects enable | 关闭网络重定向 |
| undo icmp name host-redirect receive | undo ip redirects enable | 关闭主机重定向 |
| undo icmp name timestamp-request | undo icmp timestamp receive enable | 关闭时间戳 |
| undo icmp name timestamp-reply | undo icmp timestamp receive enable | 关闭时间戳应答 |
| undo icmp type 17 | undo icmp mask request receive enable | 关闭掩码请求 |
| undo icmp type 18 | undo icmp mask reply receive enable | 关闭掩码应答 |
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论