User's Manual
370
Note:
1、 The IGMP attack prevention and the IP attack prevention cannot be started up together.
2. IP, ICMP, ICMPv6 and DHCP filter take effect only in global and interface configuration mode.
49.3.2 Enabling the Attack Prevention Function
After all parameters for attack prevention are set, you can start up the attack prevention function. Note that
small parts of processor source will be occupied when the attack prevention function is started.
Command Purpose
Switch_config# filter enable Enables the attack prevention
function.
Switch_config# filter mode [ raw |
hybrid ]
Sets the mode of Filter: Raw or Hybrid.
Use the no filter enable command to disable the attack prevention function and remove the block to all attack
sources.
49.3.3 Checking the State of Attack Prevention
After attack prevention is started, you can run the following command to check the state of attack prevention:
Command Purpose
show filter
After attack prevention is started, you
can run the following command to
check the state of attack prevention:
show filter summary
Checks the parameter configuration
and summary information of Filter.