The firewall defend port-scan enable command enables the port scanning attack defense.
The undo firewall defend port-scan enable command disables the port scanning attack defense.
By default, the port scanning attack defense is disabled.
After you configure port scanning attack defense, the FW detects the received TCP and UDP packets. If the number of packets with different destination ports from a specific source IP address per second exceeds the threshold, the FW determines that the host at this IP address launches port scanning attacks, blacklists this IP address, and processes the packets as follows:
If a source IP address is whitelisted, port scan attack defense will not be implemented for the source IP address.