< Home

anti-ddos syn-flood defend alert-rate

Function

The anti-ddos syn-flood defend alert-rate command sets the alarm threshold that triggers global source authentication defense against SYN flood attacks.

The undo anti-ddos syn-flood defend command restores the default alarm threshold (2000 pps).

Format

anti-ddos syn-flood defend [ alert-rate alert-rate ]

undo anti-ddos syn-flood defend

Parameters

Parameter Description Value
alert-rate alert-rate Specifies the SYN packet rate threshold that triggers global source authentication defense against SYN flood attacks. The value is an integer ranging from 1 to 80000000, in pps. The default value is 2000.

Views

System view

Default Level

2: Configuration level

Usage Guidelines

If alert-rate is not specified, the default alarm threshold is used.

After the anti-ddos syn-flood source-detect command is executed to enable the global source authentication defense against SYN flood attacks, the defense is triggered when the rate of SYN packets destined for the same destination IP address reaches the alarm threshold.

Example

# Set the alarm threshold for triggering global source authentication defense against SYN flood attacks to 1000 pps.

<sysname> system-view
[sysname] anti-ddos syn-flood defend alert-rate 1000
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >