H3C Technologies H3C SecPath F1000-E User Manual

Page 30

Advertising
background image

22

Figure 22 Enabling the blacklist feature

Perform the following operations on the page:

In the Global Configuration area, select the Enable Blacklist option.

Click Apply.

# Configure scanning detection for the untrusted zone.
From the navigation tree, select Intrusion Detection > Traffic abnormality > Scanning Detection. The

scanning detection configuration page appears, as shown in

Figure 23

.

Figure 23 Configuring scanning detection for the untrusted zone

Perform the following operations on the page:

Select zone Untrust.

Select the Enable Scanning Detection option.

Set the scanning threshold to 4500 connections per second.

Select the Add the source IP to the blacklist option.

Click Apply.

# Configure connection limits for the trusted zone.
From the navigation tree, select Intrusion Detection > Traffic Abnormality > Connection Limit. The

connection limit configuration page appears, as shown in

Figure 24

.

Advertising