< Home

snmp-agent blacklist ip-block disable

Function

The snmp-agent blacklist ip-block disable command disables the IP address blacklist function.

The undo snmp-agent blacklist ip-block disable command enables the IP address blacklist function..

By default, the IP address blacklist function is enabled.

Format

snmp-agent blacklist ip-block disable

undo snmp-agent blacklist ip-block disable

Parameters

None

Views

System view

Default Level

3: Management level

Usage Guidelines

Usage Scenario

If SNMP authentication fails, the IP address of the user or community is blacklisted, and this IP address cannot be used to establish a connection.

After the IP address blacklist function is enabled, if an IP address fails the authentication for the first time, the system locks the IP address for 8 seconds. The IP address will be locked for 16 seconds after the second failure and for 32 seconds after the third failure. Then the IP address will be locked for 5 minutes each time from the fourth failure and on. When the lock period expires, the IP address is automatically unlocked.

Precautions

After the IP address blacklist function is disabled, IP addresses of users who fail to be authenticated are not locked. The device is vulnerable to attacks and cracking by unauthorized users, affecting device security. Therefore, you are advised to enable the IP blacklist function.

After the IP address blacklist function is disabled, locked IP addresses are unlocked immediately.

Example

# Disable the IP address blacklist function.

<sysname> system-view
[sysname] snmp-agent blacklist ip-block disable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >