ZXR108900SeriesUserManual(BasicCongurationVolume)
protocolpacketsattackingCPU.Whensuchalarmappears,disable
protocolprotectionfunctiontoprotectCPUfrombeingattacked.
Note:
AfterprotocolprotectionfunctionsofSNMPandRADIUSaredis-
abled,theyarenotaffectedandworknormally.
ForIPv4andIPv6protocols,thereisathresholdvalue.Bydefault,
thethresholdvalueis3000,thatis,systemallowsreceiving3000
messagesofaprotocolwithin30seconds.Whentherearemore
than3000messagesreceived,alarmappears.Thethresholdvalue
canbecongured.
CPUAttackProtection
Principle
ProtocolprotectionistoprotecttheCPUofaswitch.IfCPUisat-
tackedbymanyprotocolmessages,CPUusageratiowillincrease.
WhenprotocolmessagesaresenttoCPUatahighspeed,protocol
protectionmodulewillcounttheprotocolmessagesofeachtype.
Controlledbyatimer ,thenumberofprotocolmessagessentto
CPUduringacycleiscomparedwithaconguredthresholdvalue.
Forexample,thenumberofprotocolmessagessenttoCPUwithin
30secondsisbiggerthantheconguredthresholdvalue,system
sendsapieceofalarminformationinformatof“Receivetoomany
packetsof’protocolmessagetype’fromport’portnumber’”.This
indicatestheuserthattheremaybeattackofsometypeofproto-
colmessageonaport.Iftheuserconsidersthisisanattack,the
usercandisablethistypeofprotocolprotection.Therefore,this
typeofprotocolmessagescannotbesenttoswitchplatformand
cannotattackCPUanumore.Whentheuserconsidersthatthe
attackstops,theusercanenableprotocolprotectionagainand
normalmessagesofthisprotocolcanbesenttoCPUtobepro-
cessed.
ConfiguringCPUAttack
Protection
ConfiguringIPv4ProtocolProtection
IPv4andIPv6protocolprotectionisconguredininterfacecong-
urationmode.Soitmodiesthisfunctionofphysicalinterfaces.
TocongureIPv4protocolprotection,performthefollowingsteps.
152CondentialandProprietaryInformationofZTECORPORATION