¡¡¡¡1¡¢ÅäÖþÙÀý£º
¡¡¡¡±¾Àý˵Ã÷ÔõÑùÔÚ·ÓÉÆ÷ÉÏËùÓÐline cards/port adapters £¬ ΪÁËÈÃÿ¿éline card or port adapterÊÕ¼¯µ½Ö÷»ú 100.10.0.1£¨±»¹¥»÷µÄ»úÆ÷£© µÄÊý¾ÝÁ÷¡£Á½·ÖÖÓºóÉú³É logÈÕÖ¾¡£ ¼Ç¼ÔÚlogµÄÊý¾Ý°üºÍÁ÷ÿ60ÃëÏòGRP/RSP µ¼³öÒÔ·½±ã²ì¿´¡£
Router# configure interface Router(config)# ip source-track 100.10.0.1 Router(config)# ip source-track syslog-interval 2 Router(config)# ip source-track export-interval 60 |
¡¡¡¡ÏÔʾµ½´ïÔ´¶Ë¿ÚµÄ¹¥»÷°üµÄÔ´µØÖ·¼°Á÷Á¿£º
Router# show ip source-track Address SrcIF Bytes Pkts Bytes/s Pkts/s 10.0.0.1 PO2/0 0 0 0 0 192.168.9.9 PO1/2 131M 511M 1538 6 192.168.9.9 PO2/0 144G 3134M 6619923 143909 |
¡¡¡¡ÏÔʾËùÓй¥»÷Ô´ÌõÄ¿£º
¡¡¡¡2¡¢Cisco IOS feature ÅäÖà TCP Intercept £¨·ÀÖ¹ Denial-of-Service Attacks£©
¡¡¡¡ÅäÖ÷ÓÉÆ÷ÒÔ±£»¤·þÎñÆ÷ÃâÊÕ TCP SYN-flooding attacks.
¡¡¡¡ÒÔÏÂÅäÖö¨ÒåÁËÒ»¸öÀ©Õ¹access list 101£¬±£»¤192.168.1.0/24Íø¶ÎµÄ·þÎñÆ÷£º
Router# show ip source-track summary Address Bytes Pkts Bytes/s Pkts/s 10.0.0.1 0 0 0 0 100.10.1.1 131M 511M 1538 6 192.168.9.9 146G 3178M 6711866 145908 |
¡¡¡¡show tcp intercept connections ÏÔʾ²»ÍêÈ«ºÍÒѽ¨TCPÁ¬½Ó
| ×ÔÓÉ¹ã¸æÇø |
| ¡¡ |