The anti-ddos np-rule first-packet-check enable command enables the first-packet discarding function for SYN packets on the hardware chip.
The undo anti-ddos np-rule first-packet-check enable command disables the first-packet discarding function for SYN packets on the hardware chip.
Only the USG6610E/6620E, USG6630E/6650E, USG6635E/6655E support this command.
By default, the first-packet discarding function for SYN packets on the hardware chip is disabled.
The first-packet discarding function configured using the anti-ddos first-packet-check command is performed on the CPU. To reduce the CPU load, some models support the first-packet discarding process on the hardware chip.
The first-packet discarding function on the hardware chip takes effect only after the first-packet discarding function of the CPU (anti-ddos first-packet-check) and the hardware-based defense function (anti-ddos hardware defend enable) are enabled.