fwaccel dos config
Description
The "fwaccel dos config" (for IPv4) and "fwaccel6 dos config" (for IPv6) commands show the global configuration parameters of the Rate Limiting for DoS mitigation in SecureXL.
These global parameters apply to all configured Rate Limiting rules.
|
|
Important:
|
Syntax
|
|
Parameters and Options
|
Parameter or Option |
Description |
||
|---|---|---|---|
|
No Parameters |
Shows the applicable built-in usage. |
||
|
|
Shows the configuration parameters. |
||
|
|
This parameter is deprecated starting in R82. Use these commands: |
||
|
|
Resets the configuration parameters to their default values.
|
Example
[Expert@MyGW>:0]# fwaccel dos config get
Rate Limit Rules:
Status on (without policy)
Internal Interfaces off
Monitor-Only off
Log Drops on
Max Notifications Per-Second 100 logs/second
Rule Cache on
Penalty Box:
Status off
Internal Interfaces off
Monitor-Only off
Log Drops on
Max Notifications Per-Second 100 logs/second
Send TCP Reset off
Timeout for Blocked IPs 180 seconds
Has Blocked IPs no
Log when a new IP is blocked on
Drop rate to trigger on 500 packets/second
Deny List:
Status on (without policy)
Internal Interfaces off
Monitor-Only off
Log Drops on
Max Notifications Per-Second 100 logs/second
Send TCP Reset off
Name Deny List
Disallow IPv4 Fragments:
Status off
Internal Interfaces off
Monitor-Only off
Log Drops on
Max Notifications Per-Second 100 logs/second
Disallow IP Options:
Status off
Internal Interfaces off
Monitor-Only off
Log Drops on
Max Notifications Per-Second 100 logs/second
IOC deny list (from files):
Status on (without policy)
Internal Interfaces on
Monitor-Only off
Log Drops on
Send TCP Reset off
IOC monitor-only list (from files):
Status on (without policy)
Internal Interfaces on
Monitor-Only on
Log Drops on
Send TCP Reset off
IOC deny list (from external feeds):
Status on (without policy)
Internal Interfaces on
Monitor-Only off
Log Drops on
Send TCP Reset off
IOC monitor-only list (from external feeds):
Status on (without policy)
Internal Interfaces on
Monitor-Only on
Log Drops on
Send TCP Reset off
[Expert@MyGW>:0]#
|