N in, Figure 1 – H3C Technologies H3C SecPath F1000-E User Manual
Page 623
3
Figure 1 ICMP flood detection configuration page
Do the following to configure ICMP flood detection:
1.
In the Attack Prevention Policy area, specify the protection action to be taken upon detection
of an ICMP flood attack. If you do not select the Discard packets when the specified
attack is detected option, the device only collects ICMP flood attack statistics.
2.
In the ICMP Flood Configuration area, view the configured ICMP flood detection rules, or
click Add to enter the page shown in
to configure an ICMP flood detection rule.
Figure 2 Add an ICMP flood detection rule
describes the configuration items.
Table 1 ICMP flood detection configuration items
Item
Description
IP Address
Specify the IP address of the protected host.
Protected Host
Configuration
Connection Rate
Threshold
Set the maximum ICMP connection rate for the IP address.
Global Configuration
of Security Zone
Connection Rate
Threshold
Set the global maximum ICMP connection rate for each host in
the current security zone.