This section provides the operations for displaying the configuration of DDoS attack defense, threshold learning, and IP reputation.
Table 1 shows the operations for displaying the DDoS attack defense configuration.
Operation |
Command |
|---|---|
Display status information about DDoS attack defense. |
display anti-ddos defend information { system | interface interface-type interface-number } |
Display the destination IP address monitoring table. |
display anti-ddos destination-ip slot slot-id cpu cpu-id [ ip ipv4-address [ vpn-instance vpn-instance-name ] | ipv6 ipv6-address ] |
Display the source IP address monitoring table. |
display anti-ddos source-ip slot slot-id cpu cpu-id [ ip ipv4-address [ vpn-instance vpn-instance-name ] | ipv6 ipv6-address ] |
Display the status of the attack defense function. |
|
Display the interval at which attack defense logs are generated. |
Table 2 shows the operations for displaying the threshold learning configuration.
Operation |
Command |
|---|---|
Display the threshold learning result. |
display anti-ddos baseline-learn result vrf-name vsys-name |
Display the status information about the threshold learning function. |
Table 3 shows the operations for displaying the IP reputation configuration.
Operation |
Command |
|---|---|
Check whether a specified IP address exists in the IP reputation database. |
display anti-ddos ip-reputation ip-address ip-address |
Display top N source IP addresses of packets discarded due to IP reputation. |
display anti-ddos topn-statistic ip-reputation slot slot-id cpu cpu-id |